.net_framework_4.6.2_4.7_4.7.1_4.7.2 vulnerabilities
CVEs whose affected-version data names the .net_framework_4.6.2_4.7_4.7.1_4.7.2 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
19 CVEsRSS
CVE-2026-69522High· 8.8Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-62872High· 8.8.NET Framework Elevation of Privilege Vulnerability
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-65810High· 7.8.NET Framework Elevation of Privilege Vulnerability
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70354High· 7.8.NET Core Remote Code Execution Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50649High· 7.8.NET Remote Code Execution Vulnerability
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50646High· 7.8.NET Framework Remote Code Execution Vulnerability
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50647High· 7.5Active Directory Federation Server Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50650High· 7.8.NET Framework Elevation of Privilege Vulnerability
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50527High· 7.5.NET Framework Denial of Service Vulnerability
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47304High· 8.1.NET Security Feature Bypass Vulnerability
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50648High· 7.5.NET Framework Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659Medium· 6.5.NET Spoofing Vulnerability
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-47302High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50411High· 7.5Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50368High· 7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50355High· 7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50653High· 7.5Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50652High· 7.5Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.