NuGet package
microsoft.netcore.app.runtime.win-x64
pkg:nuget/microsoft.netcore.app.runtime.win-x64
Vulnerabilities (32)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-33128 | Hig | 7.3 | >= 7.0.0, < 7.0.7 | 7.0.7 | Jun 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2023-33126 | Hig | 7.3 | >= 7.0.0, < 7.0.7 | 7.0.7 | Jun 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2023-28260 | Hig | 7.8 | >= 6.0.0, < 6.0.16 | 6.0.16 | Apr 11, 2023 | .NET DLL Hijacking Remote Code Execution Vulnerability | |
| CVE-2023-21808 | Hig | 7.8 | >= 7.0.0, < 7.0.3 | 7.0.3 | Feb 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2023-21538 | Hig | 7.5 | >= 6.0.0, < 6.0.13 | 6.0.13 | Jan 10, 2023 | .NET Denial of Service Vulnerability | |
| CVE-2022-24512 | Med | 6.3 | >= 3.0.0, < 3.1.23 | 3.1.23 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2021-34485 | Med | 5.0 | >= 3.1.0, < 3.1.18 | 3.1.18 | Aug 12, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| CVE-2021-26423 | Hig | 7.5 | >= 3.1.0, < 3.1.18 | 3.1.18 | Aug 12, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2021-1721 | Med | 6.5 | >= 3.1.0, < 3.1.12 | 3.1.12 | Feb 25, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2020-8927 | Med | 5.3 | >= 3.0.0, < 3.1.23 | 3.1.23 | Sep 15, 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to upda | |
| CVE-2020-1147 | Hig | 7.8 | KEV | >= 3.1.0, < 3.1.6 | 3.1.6 | Jul 14, 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. |
| CVE-2020-1108 | Hig | 7.5 | >= 3.1.0, < 3.1.4 | 3.1.4 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. |
- affected >= 7.0.0, < 7.0.7fixed 7.0.7
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 7.0.0, < 7.0.7fixed 7.0.7
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 6.0.0, < 6.0.16fixed 6.0.16
.NET DLL Hijacking Remote Code Execution Vulnerability
- affected >= 7.0.0, < 7.0.3fixed 7.0.3
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 6.0.0, < 6.0.13fixed 6.0.13
.NET Denial of Service Vulnerability
- affected >= 3.0.0, < 3.1.23fixed 3.1.23
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 3.1.0, < 3.1.18fixed 3.1.18
.NET Core and Visual Studio Information Disclosure Vulnerability
- affected >= 3.1.0, < 3.1.18fixed 3.1.18
.NET Core and Visual Studio Denial of Service Vulnerability
- affected >= 3.1.0, < 3.1.12fixed 3.1.12
.NET Core and Visual Studio Denial of Service Vulnerability
- affected >= 3.0.0, < 3.1.23fixed 3.1.23
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to upda
- affected >= 3.1.0, < 3.1.6fixed 3.1.6
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
- affected >= 3.1.0, < 3.1.4fixed 3.1.4
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Page 2 of 2