VYPR

Bitnami package

dotnet

pkg:bitnami/dotnet

Vulnerabilities (126)

  • CVE-2026-25667HigMar 19, 2026
    affected >= 8.0.0, < 8.0.22fixed 8.0.22

    ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.

  • CVE-2026-26131HigMar 10, 2026
    affected >= 10.0.0, < 10.0.4fixed 10.0.4

    Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26127HigMar 10, 2026
    affected >= 9.0.0, < 9.0.14fixed 9.0.14

    Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-21218HigFeb 10, 2026
    affected >= 8.0.0, < 8.0.24fixed 8.0.24

    Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-55248MedOct 14, 2025
    affected >= 8.0.0, < 8.0.21fixed 8.0.21

    Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

  • CVE-2025-55247HigOct 14, 2025
    affected >= 8.0.0, < 8.0.21fixed 8.0.21

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2025-36855HigSep 8, 2025
    affected >= 6.0.0, < 6.0.36fixed 6.0.36

    A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mecha

  • CVE-2025-36854HigSep 8, 2025
    affected >= 6.0.0, < 8.0.1fixed 8.0.1

    A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use After

  • CVE-2025-36853HigSep 8, 2025
    affected >= 6.0.0, < 6.0.36fixed 6.0.36

    A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory,

  • CVE-2025-7326HigJul 8, 2025
    affected >= 6.0.0, < 8.0.1fixed 8.0.1

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry

  • CVE-2025-30399HigJun 13, 2025
    affected >= 8.0.0, < 8.0.18fixed 8.0.18

    Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

  • CVE-2020-36846CriMay 30, 2025
    affected >= 5.0.0, < 5.0.15fixed 5.0.15

    A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression

  • CVE-2025-26646HigMay 13, 2025
    affected >= 8.0.0, < 8.0.16fixed 8.0.16

    External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-21176HigJan 14, 2025
    affected >= 8.0.0, < 8.0.1fixed 8.0.1

    .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

  • CVE-2025-21173HigJan 14, 2025
    affected >= 8.0.0, < 8.0.1fixed 8.0.1

    .NET Elevation of Privilege Vulnerability

  • CVE-2025-21172HigJan 14, 2025
    affected >= 8.0.0, < 8.0.1fixed 8.0.1

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2025-21171HigJan 14, 2025
    affected >= 9.0.0, < 9.0.1fixed 9.0.1

    .NET Remote Code Execution Vulnerability

  • CVE-2024-43499HigNov 12, 2024
    affected >= 9.0.0, < 9.0.1fixed 9.0.1

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2024-43498CriNov 12, 2024
    affected >= 9.0.0, < 9.0.1fixed 9.0.1

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2024-43485HigOct 8, 2024
    affected >= 6.0.0, < 6.0.35fixed 6.0.35

    .NET and Visual Studio Denial of Service Vulnerability

Page 3 of 7