Bitnami package
dotnet-sdk
pkg:bitnami/dotnet-sdk
Vulnerabilities (121)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-70354 | Hig | 7.8 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| CVE-2026-62909 | Hig | 7.8 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-62902 | Med | 6.5 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-62901 | Hig | 7.5 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-62900 | Med | 5.9 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-62899 | Med | 5.9 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-62898 | Hig | 7.5 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-62897 | Hig | 7.0 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| CVE-2026-62886 | Hig | 7.8 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-62871 | Hig | 7.8 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| CVE-2026-58641 | Hig | 7.8 | >= 8.0.0, < 8.0.30 | 8.0.30 | Aug 11, 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-50659 | Med | 6.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |
| CVE-2026-50651 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-50650 | Hig | 7.8 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-50649 | Hig | 7.8 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |
| CVE-2026-50648 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-50646 | Hig | 7.8 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | |
| CVE-2026-50528 | Hig | 8.2 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-50527 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-50526 | Hig | 7.0 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- affected >= 8.0.0, < 8.0.30fixed 8.0.30
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Page 1 of 7