VendorsMicrosoft.net_framework3.5
Vulnerabilities

Microsoft .net Framework 3.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

152CVEs
CVE-2013-3134
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
Published 2013-07-10 · Modified
9.3EPSS 0.210
CVE-2015-2504
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code Access Security restrictions via a crafted .NET Framework application, aka ".NET Elevation of Privilege Vulnerability."
Published 2015-09-09 · Modified
9.3EPSS 0.210
CVE-2009-0090
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
Published 2009-10-14 · Modified
9.3EPSS 0.210
CVE-2013-3133
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
Published 2013-07-10 · Modified
9.3EPSS 0.206
CVE-2013-3171
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
Published 2013-07-10 · Modified
9.3EPSS 0.206
CVE-2020-0605
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.
Published 2020-01-14 · Modified
9.3EPSS 0.178
CVE-2020-0606
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
Published 2020-01-14 · Modified
9.3EPSS 0.172
CVE-2015-1673
The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."
Published 2015-05-13 · Modified
9.3EPSS 0.169
CVE-2011-0664
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
Published 2011-06-16 · Modified
9.3EPSS 0.160
CVE-2019-0613
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual Studio Remote Code Execution Vulnerability'.
Published 2019-03-06 · Modified
9.3EPSS 0.154
CVE-2020-1046
.NET Framework Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.038
CVE-2023-36899
ASP.NET Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
8.8EPSS 0.767
CVE-2019-1113
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
Published 2019-07-29 · Modified
8.8EPSS 0.100
CVE-2023-36560
ASP.NET Security Feature Bypass Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.029
CVE-2025-21176
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Published 2025-01-14 · Modified
8.8EPSS 0.023
CVE-2026-62872
.NET Framework Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
8.8EPSS 0.008
CVE-2024-0056
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
8.7EPSS 0.012
CVE-2012-2519
Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
Published 2012-11-14 · Modified
7.9EPSS 0.032
CVE-2020-1147
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
7.8KEV2 PoCEPSS 0.940
CVE-2013-3861
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."
Published 2013-10-09 · Modified
7.8EPSS 0.824
CVE-2013-0005
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
Published 2013-01-09 · Modified
7.8EPSS 0.321
CVE-2013-3860
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, aka "Entity Expansion Vulnerability."
Published 2013-10-09 · Modified
7.8EPSS 0.306
CVE-2017-0160
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
Published 2017-04-12 · Modified
7.81 PoCEPSS 0.178
CVE-2026-50649
.NET Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.040
CVE-2026-50646
.NET Framework Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.040
CVE-2022-26929
.NET Framework Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
7.8EPSS 0.016
CVE-2018-1039
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Published 2018-05-09 · Modified
7.8EPSS 0.013
CVE-2018-8202
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
7.8EPSS 0.013
CVE-2023-36793
Visual Studio Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.8EPSS 0.012
CVE-2023-36792
Visual Studio Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.8EPSS 0.012
CVE-2023-36796
Visual Studio Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.8EPSS 0.012
CVE-2023-36794
Visual Studio Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.8EPSS 0.012
CVE-2023-24897
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
7.8EPSS 0.012
CVE-2022-41089
.NET Framework Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.012
CVE-2023-21808
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.8EPSS 0.011
CVE-2023-24895
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
7.8EPSS 0.011
CVE-2023-36788
.NET Framework Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.8EPSS 0.010
CVE-2023-29326
.NET Framework Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
7.8EPSS 0.009
CVE-2026-50650
.NET Framework Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.005
CVE-2026-65810
.NET Framework Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.004
← Prev2 / 4Next →