Skip to main content

Vendor/product archive

microsoft / .net_framework CVEs

Beta · best-effort

185 CVEs tagged to microsoft / .net_framework61 Critical, 80 High, 41 Medium, 3 Low, 0 Unrated.

CVE-2015-2456

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-2455

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-2435

Published Aug 15, 2015

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Offic…

CVSS 9.3 · Critical

CVE-2015-1673

Published May 13, 2015

The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1672

Published May 13, 2015

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted enc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1671

Published May 13, 2015

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2…

CVSS 7.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2015-1670

Published May 13, 2015

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1648

Published Apr 14, 2015

ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sens…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4149

Published Nov 11, 2014

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4122

Published Oct 15, 2014

Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addres…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4121

Published Oct 15, 2014

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arb…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4073

Published Oct 15, 2014

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4072

Published Sep 10, 2014

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to caus…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4062

Published Aug 12, 2014

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, which allows remote attackers to obtain sensitive add…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1806

Published May 14, 2014

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attacker…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0295

Published Feb 12, 2014

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0257

Published Feb 12, 2014

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0253

Published Feb 12, 2014

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3861

Published Oct 9, 2013

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3860

Published Oct 9, 2013

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a d…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3128

Published Oct 9, 2013

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Serv…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2013-3171

Published Jul 10, 2013

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3134

Published Jul 10, 2013

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows rem…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3133

Published Jul 10, 2013

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3132

Published Jul 10, 2013

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 101-125 of 185 CVEsPage 5 of 8