Vulnerabilities > Microsoft > NET Framework > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-02-10 CVE-2016-0033 Code Injection vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka ".NET Framework Stack Overflow Denial of Service Vulnerability."
network
low complexity
microsoft CWE-94
5.0
2015-11-11 CVE-2015-6115 Information Exposure vulnerability in Microsoft .Net Framework 2.0/3.5/3.5.1
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka ".NET ASLR Bypass."
network
microsoft CWE-200
4.3
2015-11-11 CVE-2015-6099 Cross-site Scripting vulnerability in Microsoft .Net Framework
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."
network
microsoft CWE-79
4.3
2015-11-11 CVE-2015-6096 Information Exposure vulnerability in Microsoft .Net Framework
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
network
microsoft CWE-200
4.3
2015-09-09 CVE-2015-2526 Code vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."
network
low complexity
microsoft CWE-17
5.0
2015-05-13 CVE-2015-1672 Cryptographic Issues vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability." <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674: Uncontrolled Recursion</a>
network
low complexity
microsoft CWE-310
5.0
2015-05-13 CVE-2015-1670 Information Exposure vulnerability in Microsoft .Net Framework
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allows remote attackers to obtain sensitive information from process memory via a crafted OpenType font on a web site, aka "OpenType Font Parsing Vulnerability."
network
microsoft CWE-200
4.3
2014-10-15 CVE-2014-4122 Permissions, Privileges, and Access Controls vulnerability in Microsoft .Net Framework 2.0/3.5/3.5.1
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location, aka ".NET ASLR Vulnerability."
network
microsoft CWE-264
4.3
2014-09-10 CVE-2014-4072 Resource Management Errors vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."
network
low complexity
microsoft CWE-399
5.0
2014-08-12 CVE-2014-4062 Permissions, Privileges, and Access Controls vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, and 3.5.1 does not properly implement the ASLR protection mechanism, which allows remote attackers to obtain sensitive address information via a crafted web site, aka ".NET ASLR Vulnerability."
network
microsoft CWE-264
4.3