Microsoft

.Net Framework

186 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 55.82%
  • Veröffentlicht 13.02.2013 12:04:12
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code vi...

  • EPSS 61.32%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP)...

  • EPSS 8.66%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (X...

  • EPSS 65.33%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service ...

  • EPSS 61.21%
  • Veröffentlicht 09.01.2013 18:09:39
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) o...

  • EPSS 14.98%
  • Veröffentlicht 09.01.2013 18:09:37
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML bro...

  • EPSS 9.31%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XB...

  • EPSS 48.69%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafte...

  • EPSS 0.7%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated...

  • EPSS 45.02%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitra...