Vulnerabilities > Microsoft > NET Framework

DATE CVE VULNERABILITY TITLE RISK
2017-09-13 CVE-2017-8759 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
network
microsoft CWE-20
critical
9.3
2017-07-11 CVE-2017-8585 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
network
low complexity
microsoft CWE-20
5.0
2017-05-12 CVE-2017-0248 Improper Certificate Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
network
low complexity
microsoft CWE-295
5.0
2017-04-12 CVE-2017-0160 Remote Code Execution vulnerability in Microsoft Windows .NET Framework CVE-2017-0160
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
local
low complexity
microsoft
7.2
2016-12-20 CVE-2016-7270 Cryptographic Issues vulnerability in Microsoft .Net Framework 4.6.2
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-310
5.0
2016-11-30 CVE-2016-2887 Improper Access Control vulnerability in IBM IMS Enterprise Suite 1.1/2.1/2.2
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
network
low complexity
ibm microsoft CWE-284
5.5
2016-10-14 CVE-2016-3209 Information Exposure vulnerability in Microsoft products
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
5.0
2016-07-13 CVE-2016-3255 XML External Entity Information Disclosure vulnerability in Microsoft .NET Framework
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability." <a href="http://cwe.mitre.org/data/definitions/611.html">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>
network
low complexity
microsoft
5.0
2016-05-11 CVE-2016-0149 Information Exposure vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."
network
microsoft CWE-200
4.3
2016-04-12 CVE-2016-0148 Permissions, Privileges, and Access Controls vulnerability in Microsoft .Net Framework 4.6/4.6.1
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
local
low complexity
microsoft CWE-264
7.2