CVE-2011-1253
- EPSS 19.5%
- Published 12.10.2011 02:52:43
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP...
CVE-2011-1978
- EPSS 14.26%
- Published 10.08.2011 21:55:02
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser a...
CVE-2011-1977
- EPSS 19.18%
- Published 10.08.2011 21:55:01
- Last modified 11.04.2025 00:51:21
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HT...
CVE-2011-0664
- EPSS 11.19%
- Published 16.06.2011 20:55:01
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code vi...
CVE-2011-1271
- EPSS 16.42%
- Published 10.05.2011 19:55:02
- Last modified 11.04.2025 00:51:21
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access rest...
CVE-2010-3958
- EPSS 53.79%
- Published 13.04.2011 18:55:00
- Last modified 11.04.2025 00:51:21
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted A...
CVE-2010-3228
- EPSS 57.7%
- Published 13.10.2010 19:00:45
- Last modified 11.04.2025 00:51:21
The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework ...
CVE-2010-3332
- EPSS 87.27%
- Published 22.09.2010 19:00:06
- Last modified 11.04.2025 00:51:21
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt ...
CVE-2010-1898
- EPSS 54.7%
- Published 11.08.2010 18:47:50
- Last modified 11.04.2025 00:51:21
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and deleg...
CVE-2010-2085
- EPSS 11.94%
- Published 27.05.2010 19:00:01
- Last modified 11.04.2025 00:51:21
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.