Microsoft

.Net Framework

186 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 63.82%
  • Veröffentlicht 09.10.2013 14:53:24
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML d...

  • EPSS 78.4%
  • Veröffentlicht 09.10.2013 14:53:24
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."

  • EPSS 7.06%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBA...

  • EPSS 8.61%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafte...

  • EPSS 57.69%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework ap...

  • EPSS 8.61%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser a...

  • EPSS 51.65%
  • Veröffentlicht 10.07.2013 03:46:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Serv...

  • EPSS 54.67%
  • Veröffentlicht 10.07.2013 03:46:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a craf...

  • EPSS 60.24%
  • Veröffentlicht 15.05.2013 03:36:34
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve s...

  • EPSS 22.77%
  • Veröffentlicht 15.05.2013 03:36:34
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authenti...