Vulnerabilities > Microsoft > NET Framework > Low

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2022-30130 Unspecified vulnerability in Microsoft .Net Framework
.NET Framework Denial of Service Vulnerability
local
low complexity
microsoft
3.3
2019-09-11 CVE-2019-1142 Path Traversal vulnerability in Microsoft .Net Framework
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-22
2.1
2019-05-16 CVE-2019-0864 Unspecified vulnerability in Microsoft .Net Framework
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'.
local
low complexity
microsoft
2.1
2018-07-11 CVE-2018-8356 Improper Certificate Validation vulnerability in Microsoft products
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
local
low complexity
microsoft CWE-295
2.1
2015-04-14 CVE-2015-1648 Data Processing Errors vulnerability in Microsoft .Net Framework
ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-19
2.6
2009-08-12 CVE-2009-1536 Improper Input Validation vulnerability in Microsoft .Net Framework, Windows Server 2008 and Windows Vista
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
network
high complexity
microsoft CWE-20
2.6