Visual Studio
by Microsoft
CVEs (278)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24512 | Med | 0.34 | 6.3 | 0.02 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2025-62453 | Med | 0.33 | 5.0 | 0.00 | Nov 11, 2025 | Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2021-34485 | Med | 0.33 | 5.0 | 0.01 | Aug 12, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2020-26870 | Med | 0.33 | 6.1 | 0.05 | Oct 7, 2020 | Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. | ||
| CVE-2019-1077 | Med | 0.33 | 5.0 | 0.02 | Jul 15, 2019 | An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'. | ||
| CVE-2026-62899 | Med | 0.31 | 5.9 | 0.01 | Aug 11, 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-55248 | Med | 0.31 | 4.8 | 0.01 | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | ||
| CVE-2024-30052 | Med | 0.31 | 4.7 | 0.01 | Jun 11, 2024 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2021-42319 | Med | 0.31 | 4.7 | 0.00 | Nov 10, 2021 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-30184 | Med | 0.29 | 5.5 | 0.05 | Jun 15, 2022 | .NET and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2021-34532 | Med | 0.29 | 5.5 | 0.01 | Aug 12, 2021 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2026-32175 | Med | 0.28 | 4.3 | 0.01 | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited… | ||
| CVE-2021-43908 | Med | 0.28 | 4.3 | 0.03 | Dec 15, 2021 | Visual Studio Code Spoofing Vulnerability | ||
| CVE-2020-8927 | Med | 0.28 | 5.3 | 0.03 | Sep 15, 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to… | ||
| CVE-2018-1037 | Med | 0.28 | 4.3 | 0.06 | Apr 12, 2018 | An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio. | ||
| CVE-2020-0884 | Low | 0.24 | 3.7 | 0.02 | Mar 12, 2020 | A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'. | ||
| CVE-2008-3704 | 0.07 | — | 0.56 | Aug 18, 2008 | Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows… | |||
| CVE-2006-4704 | 0.06 | — | 0.44 | Nov 1, 2006 | Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous… | |||
| CVE-2011-1976 | 0.05 | — | 0.21 | Aug 10, 2011 | Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability." | |||
| CVE-2007-4891 | 0.05 | — | 0.31 | Sep 14, 2007 | A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary… |
- risk 0.34cvss 6.3epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.33cvss 5.0epss 0.00
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
- risk 0.33cvss 5.0epss 0.01
.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.33cvss 6.1epss 0.05
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
- risk 0.33cvss 5.0epss 0.02
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'.
- risk 0.31cvss 5.9epss 0.01
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.31cvss 4.8epss 0.01
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- risk 0.31cvss 4.7epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.31cvss 4.7epss 0.00
Visual Studio Elevation of Privilege Vulnerability
- risk 0.29cvss 5.5epss 0.05
.NET and Visual Studio Information Disclosure Vulnerability
- risk 0.29cvss 5.5epss 0.01
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited…
- risk 0.28cvss 4.3epss 0.03
Visual Studio Code Spoofing Vulnerability
- risk 0.28cvss 5.3epss 0.03
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to…
- risk 0.28cvss 4.3epss 0.06
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio.
- risk 0.24cvss 3.7epss 0.02
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.
- CVE-2008-3704Aug 18, 2008risk 0.07cvss —epss 0.56
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows…
- CVE-2006-4704Nov 1, 2006risk 0.06cvss —epss 0.44
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous…
- CVE-2011-1976Aug 10, 2011risk 0.05cvss —epss 0.21
Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
- CVE-2007-4891Sep 14, 2007risk 0.05cvss —epss 0.31
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary…
Page 13 of 14