Microsoft

.Net Framework

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 48.63%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitra...

  • EPSS 11.74%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka...

  • EPSS 50.26%
  • Veröffentlicht 12.06.2012 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework applica...

  • EPSS 57.51%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted ...

  • EPSS 55.23%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrar...

  • EPSS 57.6%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Buffer Alloc...

  • EPSS 19.03%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Co...

  • EPSS 55.8%
  • Veröffentlicht 10.04.2012 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted AS...

  • EPSS 52.27%
  • Veröffentlicht 14.02.2012 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser ...

  • EPSS 56.28%
  • Veröffentlicht 14.02.2012 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET applicati...