Microsoft

.Net Framework

222 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 25.12%
  • Veröffentlicht 09.01.2013 18:09:39
  • Zuletzt bearbeitet 16.06.2026 23:48:40

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) o...

  • EPSS 13.55%
  • Veröffentlicht 09.01.2013 18:09:37
  • Zuletzt bearbeitet 16.06.2026 23:48:40

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML bro...

  • EPSS 22.6%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:40:30

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XB...

  • EPSS 23.67%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:40:30

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafte...

  • EPSS 3.22%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:41:37

Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated...

  • EPSS 24.76%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:45:42

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitra...

  • EPSS 24.76%
  • Veröffentlicht 14.11.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:45:42

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka...

  • EPSS 20.5%
  • Veröffentlicht 12.06.2012 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:40:26

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework applica...

  • EPSS 22.89%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:36:48

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted ...

  • EPSS 22.26%
  • Veröffentlicht 09.05.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:36:48

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrar...