Search Results (206 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2010-2085 1 Microsoft 1 .net Framework 2025-04-11 N/A
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
CVE-2013-3128 1 Microsoft 9 .net Framework, Windows 7, Windows 8 and 6 more 2025-04-11 N/A
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
CVE-2022-26929 1 Microsoft 12 .net, .net Framework, Windows 10 and 9 more 2025-03-11 7.8 High
.NET Framework Remote Code Execution Vulnerability
CVE-2023-21808 1 Microsoft 25 .net, .net Framework, Visual Studio 2017 and 22 more 2025-02-28 7.8 High
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2023-29331 2 Microsoft, Redhat 17 .net, .net Framework, Windows 10 1507 and 14 more 2025-02-28 7.5 High
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2022-41064 1 Microsoft 13 .net, .net Framework, Nuget and 10 more 2025-01-02 5.8 Medium
.NET Framework Information Disclosure Vulnerability
CVE-2022-26832 1 Microsoft 12 .net, .net Framework, Windows 10 and 9 more 2025-01-02 7.5 High
.NET Framework Denial of Service Vulnerability
CVE-2022-21911 1 Microsoft 11 .net, .net Framework, Windows 10 and 8 more 2025-01-02 7.5 High
.NET Framework Denial of Service Vulnerability
CVE-2023-36899 1 Microsoft 11 .net, .net Framework, Windows 10 1809 and 8 more 2025-01-01 8.8 High
ASP.NET Elevation of Privilege Vulnerability
CVE-2023-36873 1 Microsoft 13 .net, .net Framework, Windows 10 1607 and 10 more 2025-01-01 7.4 High
.NET Framework Spoofing Vulnerability
CVE-2023-32030 1 Microsoft 14 .net, .net Framework, Windows 10 1507 and 11 more 2025-01-01 7.5 High
.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-29326 1 Microsoft 14 .net, .net Framework, Windows 10 1507 and 11 more 2025-01-01 7.8 High
.NET Framework Remote Code Execution Vulnerability
CVE-2023-24936 2 Microsoft, Redhat 19 .net, .net Framework, Powershell and 16 more 2025-01-01 7.5 High
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
CVE-2023-24895 1 Microsoft 17 .net, .net Framework, Powershell and 14 more 2025-01-01 7.8 High
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2023-24897 1 Microsoft 19 .net, .net Framework, Powershell and 16 more 2025-01-01 7.8 High
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2023-21722 1 Microsoft 23 .net, .net Framework, Windows 10 1507 and 20 more 2025-01-01 5 Medium
.NET Framework Denial of Service Vulnerability
CVE-2021-27434 2 Microsoft, Unified-automation 2 .net Framework, .net Based Opc Ua Client\/server Sdk 2024-11-21 7.5 High
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
CVE-2021-24111 1 Microsoft 10 .net, .net Framework, Windows 10 and 7 more 2024-11-21 7.5 High
.NET Framework Denial of Service Vulnerability
CVE-2020-1108 2 Microsoft, Redhat 17 .net, .net Core, .net Framework and 14 more 2024-11-21 7.5 High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
CVE-2020-1066 1 Microsoft 3 .net Framework, Windows 7, Windows Server 2008 2024-11-21 7.8 High
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.