CVE-2007-0042
- EPSS 76.15%
- Veröffentlicht 10.07.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:34:45
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechani...
CVE-2007-0043
- EPSS 30.67%
- Veröffentlicht 10.07.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:34:45
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer,...
CVE-2006-7192
- EPSS 22.81%
- Veröffentlicht 10.04.2007 22:19:00
- Zuletzt bearbeitet 16.06.2026 22:34:33
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via...
CVE-2006-3436
- EPSS 37.77%
- Veröffentlicht 10.10.2006 21:07:00
- Zuletzt bearbeitet 16.06.2026 22:27:03
Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
- EPSS 37.16%
- Veröffentlicht 11.07.2006 21:05:00
- Zuletzt bearbeitet 16.06.2026 22:22:23
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly b...
- EPSS 13.67%
- Veröffentlicht 30.03.2006 01:06:00
- Zuletzt bearbeitet 16.06.2026 22:23:05
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file wi...
CVE-2006-1511
- EPSS 7.95%
- Veröffentlicht 30.03.2006 01:06:00
- Zuletzt bearbeitet 16.06.2026 22:23:05
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
CVE-2005-2127
- EPSS 63.67%
- Veröffentlicht 19.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:19
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for...
CVE-2005-0509
- EPSS 15.95%
- Veröffentlicht 14.03.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:16
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to norm...
CVE-2004-0200
- EPSS 49.02%
- Veröffentlicht 28.09.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:08
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to...