Skip to main content

Vendor/product archive

microsoft / .net_framework CVEs

Beta · best-effort

185 CVEs tagged to microsoft / .net_framework61 Critical, 80 High, 41 Medium, 3 Low, 0 Unrated.

CVE-2013-3129

Published Jul 10, 2013

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows X…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2013-1337

Published May 15, 2013

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1336

Published May 15, 2013

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0005

Published Jan 9, 2013

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Win…

CVSS 7.8 · High

CVE-2013-0004

Published Jan 9, 2013

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers…

CVSS 9.3 · Critical

CVE-2013-0003

Published Jan 9, 2013

Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to e…

CVSS 9.3 · Critical

CVE-2013-0002

Published Jan 9, 2013

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to exe…

CVSS 9.3 · Critical

CVE-2013-0001

Published Jan 9, 2013

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remo…

CVSS 4.3 · Medium

CVE-2012-4777

Published Nov 14, 2012

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to…

CVSS 9.3 · Critical

CVE-2012-0164

Published May 9, 2012

Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0162

Published May 9, 2012

Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2)…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0161

Published May 9, 2012

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0160

Published May 9, 2012

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0163

Published Apr 10, 2012

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 126-150 of 185 CVEsPage 6 of 8