VYPR

by Microsoft

Source repositories

CVEs (19)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-26131Hig0.517.80.00Mar 10, 2026Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-33116Hig0.497.50.01Apr 14, 2026Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-32203Hig0.497.50.00Apr 14, 2026Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-32178Hig0.497.50.00Apr 14, 2026Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26171Hig0.497.50.01Apr 14, 2026Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-26127Hig0.497.50.00Mar 10, 2026Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-25667Hig0.437.50.14Mar 19, 2026ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
CVE-2021-241110.020.25Feb 25, 2021.NET Framework Denial of Service Vulnerability
CVE-2021-319570.010.09Jun 8, 2021ASP.NET Core Denial of Service Vulnerability
CVE-2021-17210.010.09Feb 25, 2021.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2020-169370.010.09Oct 16, 2020<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.</p> <p>The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.</p>
CVE-2020-10460.010.11Aug 17, 2020A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The security update addresses the vulnerability by correcting how .NET Framework processes input.
CVE-2021-413550.000.04Oct 13, 2021.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-344850.000.01Aug 12, 2021.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-264230.000.03Aug 12, 2021.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2021-312040.000.04May 11, 2021.NET and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-267010.000.03Feb 25, 2021.NET Core Remote Code Execution Vulnerability
CVE-2021-241120.000.01Feb 25, 2021.NET Core Remote Code Execution Vulnerability
CVE-2020-14760.000.01Aug 17, 2020An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an attacker would need to send a specially crafted request to an affected server. The update addresses the vulnerability by changing how ASP.NET and .NET handle requests.