Microsoft .net Framework
Microsoft · 12 CVEs
Core: NCL - SocketsHttpHandler mishandling 1xx response as a final response leads to info disclosure
Jan 8, 2019
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".…
Dec 12, 2018
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framewo…
Dec 12, 2018
NET: RCE when processing untrusted input
Sep 13, 2018
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access infor…
Aug 15, 2018
Core: incorrect certificates validation
Jul 11, 2018
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".…
Jul 11, 2018
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a f…
Jul 11, 2018
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privile…
Jul 11, 2018
dotnet: Device Guard security bypass can allow for privilege escalation
May 9, 2018
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely v…
Sep 13, 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Securit…
May 12, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-0545 | Core: NCL - SocketsHttpHandler mishandling 1xx response as a final response leads to info disclosure | HIGH | 9.61% | Jan 8, 2019 |
| CVE-2018-8540 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vuln… | CRITICAL | 21.57% | Dec 12, 2018 |
| CVE-2018-8517 | A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." Thi… | HIGH | 5.67% | Dec 12, 2018 |
| CVE-2018-8421 | NET: RCE when processing untrusted input | CRITICAL | 29.07% | Sep 13, 2018 |
| CVE-2018-8360 | An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka… | HIGH | 8.97% | Aug 15, 2018 |
| CVE-2018-8356 | Core: incorrect certificates validation | MEDIUM | 0.75% | Jul 11, 2018 |
| CVE-2018-8284 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vuln… | HIGH | 41.53% | Jul 11, 2018 |
| CVE-2018-8260 | A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Exe… | HIGH | 15.53% | Jul 11, 2018 |
| CVE-2018-8202 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation… | HIGH | 1.31% | Jul 11, 2018 |
| CVE-2018-1039 | dotnet: Device Guard security bypass can allow for privilege escalation | HIGH | 1.32% | May 9, 2018 |
| CVE-2017-8759 KEV | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application,… | HIGH | 88.70% | Sep 13, 2017 |
| CVE-2017-0248 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a cer… | HIGH | 5.51% | May 12, 2017 |
Showing 1 to 12 of 12 CVEs