CVE-2010-3958
- EPSS 23.59%
- Veröffentlicht 13.04.2011 18:55:00
- Zuletzt bearbeitet 16.06.2026 23:23:53
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted A...
CVE-2010-3228
- EPSS 19.4%
- Veröffentlicht 13.10.2010 19:00:45
- Zuletzt bearbeitet 16.06.2026 23:22:24
The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework ...
CVE-2010-3332
- EPSS 67.48%
- Veröffentlicht 22.09.2010 19:00:06
- Zuletzt bearbeitet 16.06.2026 23:22:36
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt ...
CVE-2010-1898
- EPSS 25.03%
- Veröffentlicht 11.08.2010 18:47:50
- Zuletzt bearbeitet 16.06.2026 23:19:33
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and deleg...
CVE-2010-2085
- EPSS 9%
- Veröffentlicht 27.05.2010 19:00:01
- Zuletzt bearbeitet 16.06.2026 23:19:57
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
CVE-2009-2497
- EPSS 23.25%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:35
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser appl...
CVE-2009-2500
- EPSS 23.65%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:35
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP...
CVE-2009-2501
- EPSS 26.82%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:35
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 G...
CVE-2009-2502
- EPSS 22.03%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:35
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3...
CVE-2009-2503
- EPSS 22.21%
- Veröffentlicht 14.10.2009 10:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:35
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold a...