NuGet package
microsoft.netcore.app.runtime.win-arm
pkg:nuget/microsoft.netcore.app.runtime.win-arm
Vulnerabilities (27)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-24512 | Med | 6.3 | >= 3.0.0, < 3.1.23 | 3.1.23 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2021-34485 | Med | 5.0 | >= 3.1.0, < 3.1.18 | 3.1.18 | Aug 12, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| CVE-2021-26423 | Hig | 7.5 | >= 3.1.0, < 3.1.18 | 3.1.18 | Aug 12, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2021-1721 | Med | 6.5 | >= 3.1.0, < 3.1.12 | 3.1.12 | Feb 25, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2020-8927 | Med | 5.3 | >= 3.0.0, < 3.1.23 | 3.1.23 | Sep 15, 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to upda | |
| CVE-2020-1147 | Hig | 7.8 | KEV | >= 3.1.0, < 3.1.6 | 3.1.6 | Jul 14, 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. |
| CVE-2020-1108 | Hig | 7.5 | >= 3.1.0, < 3.1.4 | 3.1.4 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exp |
- affected >= 3.0.0, < 3.1.23fixed 3.1.23
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 3.1.0, < 3.1.18fixed 3.1.18
.NET Core and Visual Studio Information Disclosure Vulnerability
- affected >= 3.1.0, < 3.1.18fixed 3.1.18
.NET Core and Visual Studio Denial of Service Vulnerability
- affected >= 3.1.0, < 3.1.12fixed 3.1.12
.NET Core and Visual Studio Denial of Service Vulnerability
- affected >= 3.0.0, < 3.1.23fixed 3.1.23
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to upda
- affected >= 3.1.0, < 3.1.6fixed 3.1.6
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
- affected >= 3.1.0, < 3.1.4fixed 3.1.4
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exp
Page 2 of 2