.net Framework
by Microsoft
CVEs (207)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32177 | Hig | 0.47 | 7.3 | 0.01 | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-50650 | Hig | 0.44 | 7.8 | 0.00 | Jul 14, 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-50649 | Hig | 0.44 | 7.8 | 0.01 | Jul 14, 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50646 | Hig | 0.44 | 7.8 | 0.01 | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | ||
| CVE-2022-41089 | Hig | 0.44 | 7.8 | 0.01 | Dec 13, 2022 | .NET Framework Remote Code Execution Vulnerability | ||
| CVE-2019-11397 | Med | 0.43 | 6.5 | 0.05 | May 14, 2019 | GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter. | ||
| CVE-2016-3209 | Med | 0.43 | 5.5 | 0.54 | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for… | ||
| CVE-2026-50659 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-33116 | Hig | 0.42 | 7.5 | 0.02 | Apr 14, 2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | ||
| CVE-2023-36042 | Med | 0.40 | 6.2 | 0.01 | Nov 14, 2023 | Visual Studio Denial of Service Vulnerability | ||
| CVE-2026-62897 | Hig | 0.39 | 7.0 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||
| CVE-2019-0657 | Med | 0.39 | 5.9 | 0.05 | Mar 5, 2019 | A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | ||
| CVE-2016-0149 | Med | 0.39 | 5.9 | 0.08 | May 11, 2016 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure… | ||
| CVE-2026-32226 | Med | 0.38 | 5.9 | 0.01 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2022-41064 | Med | 0.38 | 5.8 | 0.01 | Nov 9, 2022 | .NET Framework Information Disclosure Vulnerability | ||
| CVE-2020-1476 | Med | 0.36 | 5.5 | 0.01 | Aug 17, 2020 | An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an… | ||
| CVE-2019-1142 | Med | 0.36 | 5.5 | 0.01 | Sep 11, 2019 | An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0864 | Med | 0.36 | 5.5 | 0.01 | May 16, 2019 | A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'. | ||
| CVE-2018-8356 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2018 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework… | ||
| CVE-2023-21722 | Med | 0.33 | 5.0 | 0.01 | Feb 14, 2023 | .NET Framework Denial of Service Vulnerability |
- risk 0.47cvss 7.3epss 0.01
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
- risk 0.44cvss 7.8epss 0.00
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- risk 0.44cvss 7.8epss 0.01
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- risk 0.44cvss 7.8epss 0.01
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- risk 0.44cvss 7.8epss 0.01
.NET Framework Remote Code Execution Vulnerability
- risk 0.43cvss 6.5epss 0.05
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
- risk 0.43cvss 5.5epss 0.54
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…
- risk 0.42cvss 6.5epss 0.01
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 7.5epss 0.02
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
- risk 0.40cvss 6.2epss 0.01
Visual Studio Denial of Service Vulnerability
- risk 0.39cvss 7.0epss 0.00
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- risk 0.39cvss 5.9epss 0.05
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
- risk 0.39cvss 5.9epss 0.08
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure…
- risk 0.38cvss 5.9epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.8epss 0.01
.NET Framework Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an…
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
- risk 0.36cvss 5.5epss 0.01
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'.
- risk 0.36cvss 5.5epss 0.01
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework…
- risk 0.33cvss 5.0epss 0.01
.NET Framework Denial of Service Vulnerability
Page 5 of 11