Asp.Net

Vendor:

First CVE: Sep 22, 2003 · Active for 22 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Asp.Net over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2003
22 years ago
Most Recent CVE
May 27, 2010
5,902 days ago

CVE Severity & Scoring

Asp.Net9 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None2 (22.2%)
Unknown7 (77.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a
Nov 3, 20049.880NOYES
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a
Mar 23, 20067.559NOYES
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode represe
Feb 16, 20054.333NOYES
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested
May 18, 20055.031NONO
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encod
Jul 12, 20055.024NONO
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) r
May 18, 20056.424NONO
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
Sep 22, 20036.823NONO
Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scri
May 27, 20104.320NONO
ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form contr
May 27, 20104.318NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Asp.Net

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.514.39.0%00
2.014.312.5%00
1.166.335.6%03
1.034.925.9%01