.net Framework
by Microsoft
CVEs (207)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29331 | Hig | 0.49 | 7.5 | 0.03 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-24936 | Hig | 0.49 | 7.5 | 0.02 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-26832 | Hig | 0.49 | 7.5 | 0.03 | Apr 15, 2022 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2022-21911 | Hig | 0.49 | 7.5 | 0.03 | Jan 11, 2022 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2021-24111 | Hig | 0.49 | 7.5 | 0.04 | Feb 25, 2021 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2019-1083 | Hig | 0.49 | 7.5 | 0.08 | Jul 15, 2019 | A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'. | ||
| CVE-2019-1006 | Hig | 0.49 | 7.5 | 0.06 | Jul 15, 2019 | An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. | ||
| CVE-2019-0981 | Hig | 0.49 | 7.5 | 0.05 | May 16, 2019 | A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980. | ||
| CVE-2019-0980 | Hig | 0.49 | 7.5 | 0.05 | May 16, 2019 | A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981. | ||
| CVE-2019-0820 | Hig | 0.49 | 7.5 | 0.06 | May 16, 2019 | A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981. | ||
| CVE-2018-8517 | Hig | 0.49 | 7.5 | 0.06 | Dec 12, 2018 | A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2,… | ||
| CVE-2018-8360 | Hig | 0.49 | 7.5 | 0.09 | Aug 15, 2018 | An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft… | ||
| CVE-2018-0765 | Hig | 0.49 | 7.5 | 0.08 | May 9, 2018 | A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET… | ||
| CVE-2018-0786 | Hig | 0.49 | 7.5 | 0.04 | Jan 10, 2018 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability." | ||
| CVE-2018-0764 | Hig | 0.49 | 7.5 | 0.09 | Jan 10, 2018 | Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This… | ||
| CVE-2017-0248 | Hig | 0.49 | 7.5 | 0.06 | May 12, 2017 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." | ||
| CVE-2026-35433 | Hig | 0.48 | 7.3 | 0.01 | May 12, 2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2024-38081 | Hig | 0.48 | 7.3 | 0.01 | Jul 9, 2024 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2024-21409 | Hig | 0.48 | 7.3 | 0.03 | Apr 9, 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36873 | Hig | 0.48 | 7.4 | 0.01 | Aug 8, 2023 | .NET Framework Spoofing Vulnerability |
- risk 0.49cvss 7.5epss 0.03
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET Framework Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET Framework Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.04
.NET Framework Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.08
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.06
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
- risk 0.49cvss 7.5epss 0.06
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
- risk 0.49cvss 7.5epss 0.06
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2,…
- risk 0.49cvss 7.5epss 0.09
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft…
- risk 0.49cvss 7.5epss 0.08
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET…
- risk 0.49cvss 7.5epss 0.04
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
- risk 0.49cvss 7.5epss 0.09
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This…
- risk 0.49cvss 7.5epss 0.06
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
- risk 0.48cvss 7.3epss 0.01
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.3epss 0.01
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.03
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.48cvss 7.4epss 0.01
.NET Framework Spoofing Vulnerability
Page 4 of 11