Bitnami package
dotnet-sdk
pkg:bitnami/dotnet-sdk
Vulnerabilities (121)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-38095 | Hig | 7.5 | >= 8.0.0, < 8.0.7 | 8.0.7 | Jul 9, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-38081 | Hig | 7.3 | >= 6.0.0, < 6.0.32 | 6.0.32 | Jul 9, 2024 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2024-35264 | Hig | 8.1 | >= 8.0.0, < 8.0.7 | 8.0.7 | Jul 9, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-30105 | Hig | 7.5 | >= 8.0.0, < 8.0.8 | 8.0.8 | Jul 9, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-30046 | Med | 5.9 | >= 7.0.0, < 7.0.19 | 7.0.19 | May 14, 2024 | Visual Studio Denial of Service Vulnerability | |
| CVE-2024-30045 | Med | 6.3 | >= 7.0.0, < 7.0.19 | 7.0.19 | May 14, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-21409 | Hig | 7.3 | >= 6.0.0, < 6.0.29 | 6.0.29 | Apr 9, 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-26190 | Hig | 7.5 | >= 7.0.0, < 7.0.17 | 7.0.17 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | |
| CVE-2024-21392 | Hig | 7.5 | >= 7.0.0, < 7.0.17 | 7.0.17 | Mar 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-21319 | Med | 6.8 | >= 6.0.0, < 6.0.26 | 6.0.26 | Jan 9, 2024 | Microsoft Identity Denial of service vulnerability | |
| CVE-2024-20672 | Hig | 7.5 | >= 6.0.0, < 6.0.26 | 6.0.26 | Jan 9, 2024 | .NET Denial of Service Vulnerability | |
| CVE-2024-0057 | Cri | 9.1 | >= 6.0.0, < 6.0.26 | 6.0.26 | Jan 9, 2024 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| CVE-2024-0056 | Hig | 8.7 | >= 6.0.0, < 6.0.26 | 6.0.26 | Jan 9, 2024 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | |
| CVE-2023-36558 | Med | 6.2 | >= 6.0.0, < 6.0.25 | 6.0.25 | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability | |
| CVE-2023-36038 | Hig | 8.2 | < 8.0.0 | 8.0.0 | Nov 14, 2023 | ASP.NET Core Denial of Service Vulnerability | |
| CVE-2023-36049 | Hig | 7.6 | >= 6.0.0, < 6.0.25 | 6.0.25 | Nov 14, 2023 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2023-38171 | Hig | 7.5 | >= 7.0.0, < 7.0.12 | 7.0.12 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | |
| CVE-2023-36435 | Hig | 7.5 | >= 7.0.0, < 7.0.13 | 7.0.13 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | |
| CVE-2023-44487 | Hig | 7.5 | KEV | >= 6.0.0, < 6.0.23 | 6.0.23 | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-36799 | Med | 6.5 | >= 6.0.0, < 6.0.1 | 6.0.1 | Sep 12, 2023 | .NET Core and Visual Studio Denial of Service Vulnerability |
- affected >= 8.0.0, < 8.0.7fixed 8.0.7
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.32fixed 6.0.32
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- affected >= 8.0.0, < 8.0.7fixed 8.0.7
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 8.0.0, < 8.0.8fixed 8.0.8
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 7.0.0, < 7.0.19fixed 7.0.19
Visual Studio Denial of Service Vulnerability
- affected >= 7.0.0, < 7.0.19fixed 7.0.19
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 6.0.0, < 6.0.29fixed 6.0.29
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- affected >= 7.0.0, < 7.0.17fixed 7.0.17
Microsoft QUIC Denial of Service Vulnerability
- affected >= 7.0.0, < 7.0.17fixed 7.0.17
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.26fixed 6.0.26
Microsoft Identity Denial of service vulnerability
- affected >= 6.0.0, < 6.0.26fixed 6.0.26
.NET Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.26fixed 6.0.26
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
- affected >= 6.0.0, < 6.0.26fixed 6.0.26
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
- affected >= 6.0.0, < 6.0.25fixed 6.0.25
ASP.NET Core Security Feature Bypass Vulnerability
- affected < 8.0.0fixed 8.0.0
ASP.NET Core Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.25fixed 6.0.25
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- affected >= 7.0.0, < 7.0.12fixed 7.0.12
Microsoft QUIC Denial of Service Vulnerability
- affected >= 7.0.0, < 7.0.13fixed 7.0.13
Microsoft QUIC Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.23fixed 6.0.23
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- affected >= 6.0.0, < 6.0.1fixed 6.0.1
.NET Core and Visual Studio Denial of Service Vulnerability
Page 4 of 7