Bitnami package
dotnet
pkg:bitnami/dotnet
Vulnerabilities (121)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-26131 | Hig | 7.8 | >= 10.0.0, < 10.0.4 | 10.0.4 | Mar 10, 2026 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-26127 | Hig | 7.5 | >= 9.0.0, < 9.0.14 | 9.0.14 | Mar 10, 2026 | Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-21218 | Hig | 7.5 | >= 8.0.0, < 8.0.24 | 8.0.24 | Feb 10, 2026 | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-55248 | Med | 4.8 | >= 8.0.0, < 8.0.21 | 8.0.21 | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | |
| CVE-2025-55247 | Hig | 7.3 | >= 8.0.0, < 8.0.21 | 8.0.21 | Oct 14, 2025 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-30399 | Hig | 7.5 | >= 8.0.0, < 8.0.18 | 8.0.18 | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | |
| CVE-2020-36846 | Cri | 9.8 | >= 5.0.0, < 5.0.15 | 5.0.15 | May 30, 2025 | A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression | |
| CVE-2025-26646 | Hig | 8.0 | >= 8.0.0, < 8.0.16 | 8.0.16 | May 13, 2025 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | |
| CVE-2025-21176 | Hig | 8.8 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2025-21173 | Hig | 7.3 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET Elevation of Privilege Vulnerability | |
| CVE-2025-21172 | Hig | 7.5 | >= 8.0.0, < 8.0.1 | 8.0.1 | Jan 14, 2025 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2025-21171 | Hig | 7.5 | >= 9.0.0, < 9.0.1 | 9.0.1 | Jan 14, 2025 | .NET Remote Code Execution Vulnerability | |
| CVE-2024-43499 | Hig | 7.5 | >= 9.0.0, < 9.0.1 | 9.0.1 | Nov 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-43498 | Cri | 9.8 | >= 9.0.0, < 9.0.1 | 9.0.1 | Nov 12, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-43485 | Hig | 7.5 | >= 6.0.0, < 6.0.35 | 6.0.35 | Oct 8, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-43484 | Hig | 7.5 | >= 6.0.0, < 6.0.35 | 6.0.35 | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-43483 | Hig | 7.5 | >= 6.0.0, < 6.0.35 | 6.0.35 | Oct 8, 2024 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-38229 | Hig | 8.1 | >= 8.0.0, < 8.0.10 | 8.0.10 | Oct 8, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-38168 | Hig | 7.5 | >= 8.0.0, < 8.0.8 | 8.0.8 | Aug 13, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-38167 | Med | 6.5 | >= 8.0.0, < 8.0.8 | 8.0.8 | Aug 13, 2024 | .NET and Visual Studio Information Disclosure Vulnerability |
- affected >= 10.0.0, < 10.0.4fixed 10.0.4
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 9.0.0, < 9.0.14fixed 9.0.14
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.24fixed 8.0.24
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.21fixed 8.0.21
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- affected >= 8.0.0, < 8.0.21fixed 8.0.21
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.18fixed 8.0.18
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- affected >= 5.0.0, < 5.0.15fixed 5.0.15
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression
- affected >= 8.0.0, < 8.0.16fixed 8.0.16
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET Elevation of Privilege Vulnerability
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET Remote Code Execution Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 9.0.0, < 9.0.1fixed 9.0.1
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 6.0.0, < 6.0.35fixed 6.0.35
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.35fixed 6.0.35
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.35fixed 6.0.35
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- affected >= 8.0.0, < 8.0.10fixed 8.0.10
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 8.0.0, < 8.0.8fixed 8.0.8
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 8.0.0, < 8.0.8fixed 8.0.8
.NET and Visual Studio Information Disclosure Vulnerability
Page 3 of 7