Asp.Net
Vendor:
First CVE: Sep 22, 2003 · Active for 22 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Asp.Net over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2003
22 years ago
Most Recent CVE
May 27, 2010
5,902 days ago
CVE Severity & Scoring
Asp.Net9 CVEs
78%
11%
11%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None2 (22.2%)
Unknown7 (77.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0847CRITICAL The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a | Nov 3, 2004 | 9.8 | 80 | NO | YES |
CVE-2006-1364HIGH Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a | Mar 23, 2006 | 7.5 | 59 | NO | YES |
CVE-2005-0452MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode represe | Feb 16, 2005 | 4.3 | 33 | NO | YES |
CVE-2005-1665MEDIUM The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested | May 18, 2005 | 5.0 | 31 | NO | NO |
CVE-2005-2224MEDIUM aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encod | Jul 12, 2005 | 5.0 | 24 | NO | NO |
CVE-2005-1664MEDIUM The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) r | May 18, 2005 | 6.4 | 24 | NO | NO |
CVE-2003-0768MEDIUM Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name. | Sep 22, 2003 | 6.8 | 23 | NO | NO |
CVE-2010-2084MEDIUM Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scri | May 27, 2010 | 4.3 | 20 | NO | NO |
CVE-2010-2088MEDIUM ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form contr | May 27, 2010 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Asp.Net
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5 | 1 | 4.3 | 9.0% | 0 | 0 |
| 2.0 | 1 | 4.3 | 12.5% | 0 | 0 |
| 1.1 | 6 | 6.3 | 35.6% | 0 | 3 |
| 1.0 | 3 | 4.9 | 25.9% | 0 | 1 |