Microsoft

.Net Framework

222 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 21.04%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework ap...

  • EPSS 20.6%
  • Veröffentlicht 10.07.2013 03:46:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser a...

  • EPSS 32.38%
  • Veröffentlicht 10.07.2013 03:46:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Serv...

  • EPSS 22.01%
  • Veröffentlicht 10.07.2013 03:46:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a craf...

  • EPSS 19.26%
  • Veröffentlicht 15.05.2013 03:36:34
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve s...

  • EPSS 20.63%
  • Veröffentlicht 15.05.2013 03:36:34
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authenti...

  • EPSS 29.63%
  • Veröffentlicht 13.02.2013 12:04:12
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code vi...

  • EPSS 23.84%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 16.06.2026 23:48:40

Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP)...

  • EPSS 21.42%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 16.06.2026 23:48:41

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (X...

  • EPSS 32.1%
  • Veröffentlicht 09.01.2013 18:09:40
  • Zuletzt bearbeitet 16.06.2026 23:48:41

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service ...