Microsoft / Asp.net
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-8171 | A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vu… | HIGH | 7.5 | Jul 11, 2018 |
| CVE-2017-11883 | Core: DoS due to improper handling of web requests | HIGH | 7.5 | Nov 15, 2017 |
| CVE-2010-2088 | ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks a… | MEDIUM | 4.3 | May 27, 2010 |
| CVE-2010-2084 | Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to co… | MEDIUM | 4.3 | May 27, 2010 |
| CVE-2006-1364 | Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote… | HIGH | 7.5 | Mar 23, 2006 |
| CVE-2005-2224 | aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP me… | MEDIUM | 5.0 | Jul 12, 2005 |
| CVE-2005-1665 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumptio… | MEDIUM | 5.0 | May 18, 2005 |
| CVE-2005-1664 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a… | MEDIUM | 6.4 | May 18, 2005 |
| CVE-2005-0452 | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web scrip… | MEDIUM | 4.3 | Feb 16, 2005 |
| CVE-2004-0847 | The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a… | CRITICAL | 9.8 | Oct 6, 2004 |
| CVE-2003-0768 | Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the begi… | MEDIUM | 6.8 | Sep 12, 2003 |
Showing 1 to 9 of 9 CVEs