CVE-2013-1337
- EPSS 21.8%
- Published 15.05.2013 03:36:34
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authenti...
- EPSS 59.17%
- Published 13.02.2013 12:04:12
- Last modified 11.04.2025 00:51:21
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code vi...
CVE-2013-0003
- EPSS 61.32%
- Published 09.01.2013 18:09:40
- Last modified 11.04.2025 00:51:21
Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP)...
CVE-2013-0004
- EPSS 10.05%
- Published 09.01.2013 18:09:40
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (X...
CVE-2013-0005
- EPSS 68.16%
- Published 09.01.2013 18:09:40
- Last modified 11.04.2025 00:51:21
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service ...
CVE-2013-0002
- EPSS 61.21%
- Published 09.01.2013 18:09:39
- Last modified 11.04.2025 00:51:21
Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) o...
CVE-2013-0001
- EPSS 17.14%
- Published 09.01.2013 18:09:37
- Last modified 11.04.2025 00:51:21
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML bro...
CVE-2012-1895
- EPSS 10.78%
- Published 14.11.2012 00:55:01
- Last modified 11.04.2025 00:51:21
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XB...
- EPSS 52.25%
- Published 14.11.2012 00:55:01
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafte...
CVE-2012-2519
- EPSS 0.7%
- Published 14.11.2012 00:55:01
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated...