CVE-2009-1536
- EPSS 52.48%
- Veröffentlicht 12.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via ...
- EPSS 27.76%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attacker...
CVE-2008-3842
- EPSS 11.49%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as d...
CVE-2008-3843
- EPSS 11.67%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demo...
CVE-2007-0041
- EPSS 61.96%
- Veröffentlicht 10.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths...
CVE-2007-0042
- EPSS 84.24%
- Veröffentlicht 10.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechani...
CVE-2007-0043
- EPSS 61.96%
- Veröffentlicht 10.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer,...
CVE-2006-7192
- EPSS 19.83%
- Veröffentlicht 10.04.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via...
CVE-2006-3436
- EPSS 60.47%
- Veröffentlicht 10.10.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
- EPSS 45.43%
- Veröffentlicht 11.07.2006 21:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly b...