Product:

\.net_framework

(Microsoft)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 174
Date Id Summary Products Score Patch Annotated
2022-01-11 CVE-2022-21911 .NET Framework Denial of Service Vulnerability \.net_framework 7.5
2009-10-14 CVE-2009-2502 Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007... \.net_framework, Excel_viewer, Expression_web, Forefront_client_security, Internet_explorer, Office, Office_compatibility_pack, Office_excel_viewer, Office_groove, Office_powerpoint_viewer, Office_word_viewer, Platform_sdk, Project, Report_viewer, Sql_server, Sql_server_reporting_services, Visio, Visual_foxpro, Visual_studio, Visual_studio_\.net, Windows_2003_server, Windows_server_2008, Windows_vista, Windows_xp, Word_viewer, Works N/A
2024-10-08 CVE-2024-43483 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability \.net, \.net_framework, Visual_studio_2022 7.5
2024-10-08 CVE-2024-43484 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability \.net, \.net_framework, Visual_studio_2022 7.5
2011-05-10 CVE-2011-1271 The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET... \.net_framework N/A
2024-01-09 CVE-2024-21312 .NET Framework Denial of Service Vulnerability \.net_framework 7.5
2024-01-09 CVE-2024-0057 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability \.net, \.net_framework, Powershell, Visual_studio_2022 9.8
2024-07-09 CVE-2024-38081 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability \.net, \.net_framework, Visual_studio_2022 7.3
2017-09-13 CVE-2017-8759 Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." \.net_framework 7.8
2015-05-13 CVE-2015-1671 The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability." \.net_framework, Live_meeting, Lync, Silverlight 7.8