Vulnerabilities > Microsoft > NET Framework

DATE CVE VULNERABILITY TITLE RISK
2018-05-09 CVE-2018-0765 XXE vulnerability in Microsoft .Net Core and .Net Framework
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.
network
low complexity
microsoft CWE-611
5.0
2018-01-10 CVE-2018-0786 Improper Certificate Validation vulnerability in Microsoft .Net Core, .Net Framework and Powershell Core
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."
network
low complexity
microsoft CWE-295
5.0
2018-01-10 CVE-2018-0764 Unspecified vulnerability in Microsoft .Net Core, .Net Framework and Powershell Core
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0.
network
low complexity
microsoft
5.0
2017-09-13 CVE-2017-8759 Unspecified vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
local
low complexity
microsoft
7.8
2017-07-11 CVE-2017-8585 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
network
low complexity
microsoft CWE-20
5.0
2017-05-12 CVE-2017-0248 Improper Certificate Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
network
low complexity
microsoft CWE-295
5.0
2017-04-12 CVE-2017-0160 Remote Code Execution vulnerability in Microsoft Windows .NET Framework CVE-2017-0160
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
local
low complexity
microsoft
7.2
2016-12-20 CVE-2016-7270 Cryptographic Issues vulnerability in Microsoft .Net Framework 4.6.2
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-310
5.0
2016-11-30 CVE-2016-2887 Improper Access Control vulnerability in IBM IMS Enterprise Suite 1.1/2.1/2.2
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
network
low complexity
ibm microsoft CWE-284
5.5
2016-10-14 CVE-2016-3209 Information Exposure vulnerability in Microsoft products
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
5.0