Bitnami package
dotnet
pkg:bitnami/dotnet
Vulnerabilities (126)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-25667 | Hig | 7.5 | >= 8.0.0, < 8.0.22 | 8.0.22 | Mar 19, 2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing. | |
| CVE-2026-26131 | Hig | 7.8 | >= 10.0.0, < 10.0.4 | 10.0.4 | Mar 10, 2026 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-26127 | Hig | 7.5 | >= 9.0.0, < 9.0.14 | 9.0.14 | Mar 10, 2026 | Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-21218 | Hig | 7.5 | >= 8.0.0, < 8.0.24 | 8.0.24 | Feb 10, 2026 | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-55248 | Med | 4.8 | >= 8.0.0, < 8.0.21 | 8.0.21 | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | |
| CVE-2025-55247 | Hig | 7.3 | >= 8.0.0, < 8.0.21 | 8.0.21 | Oct 14, 2025 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-36855 | Hig | 8.8 | >= 6.0.0, < 6.0.36 | 6.0.36 | Sep 8, 2025 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mecha | |
| CVE-2025-36854 | Hig | 8.1 | >= 6.0.0, < 8.0.1 | 8.0.1 | Sep 8, 2025 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use After | |
| CVE-2025-36853 | Hig | 7.5 | >= 6.0.0, < 6.0.36 | 6.0.36 | Sep 8, 2025 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, | |
| CVE-2025-7326 | Hig | 7.0 | >= 6.0.0, < 8.0.1 | 8.0.1 | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry | |
| CVE-2025-30399 | Hig | 7.5 | >= 8.0.0, < 8.0.18 | 8.0.18 | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | |
| CVE-2020-36846 | Cri | 9.8 | >= 5.0.0, < 5.0.15 | 5.0.15 | May 30, 2025 | A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression | |
| CVE-2025-26646 | Hig | 8.0 | >= 8.0.0, < 8.0.16 | 8.0.16 | May 13, 2025 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | |
| CVE-2025-21176 | Hig | 8.8 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2025-21173 | Hig | 7.3 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET Elevation of Privilege Vulnerability | |
| CVE-2025-21172 | Hig | 7.5 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2025-21171 | Hig | 7.5 | >= 9.0.0, < 9.0.1 | 9.0.1 | Jan 14, 2025 | .NET Remote Code Execution Vulnerability | |
| CVE-2024-43499 | Hig | 7.5 | >= 9.0.0, < 9.0.1 | 9.0.1 | Nov 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-43498 | Cri | 9.8 | >= 9.0.0, < 9.0.1 | 9.0.1 | Nov 12, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-43485 | Hig | 7.5 | >= 6.0.0, < 6.0.35 | 6.0.35 | Oct 8, 2024 | .NET and Visual Studio Denial of Service Vulnerability |
- affected >= 8.0.0, < 8.0.22fixed 8.0.22
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
- affected >= 10.0.0, < 10.0.4fixed 10.0.4
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 9.0.0, < 9.0.14fixed 9.0.14
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.24fixed 8.0.24
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.21fixed 8.0.21
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- affected >= 8.0.0, < 8.0.21fixed 8.0.21
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 6.0.0, < 6.0.36fixed 6.0.36
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mecha
- affected >= 6.0.0, < 8.0.1fixed 8.0.1
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use After
- affected >= 6.0.0, < 6.0.36fixed 6.0.36
A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory,
- affected >= 6.0.0, < 8.0.1fixed 8.0.1
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry
- affected >= 8.0.0, < 8.0.18fixed 8.0.18
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- affected >= 5.0.0, < 5.0.15fixed 5.0.15
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression
- affected >= 8.0.0, < 8.0.16fixed 8.0.16
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET Elevation of Privilege Vulnerability
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET Remote Code Execution Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 6.0.0, < 6.0.35fixed 6.0.35
.NET and Visual Studio Denial of Service Vulnerability
Page 3 of 7