CVE-2019-0981
published 2019-05-16CVE-2019-0981: A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.94%
91.1th percentile
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
Affected
153 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0980 [HIGH] CWE-835 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
Red Hat
dotnet: timeouts for regular expressions are not enforced
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0820 [HIGH] CWE-400 dotnet: timeouts for regular expressions are not enforced
dotnet: timeouts for regular expressions are not enforced
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Microsoft
.Net Framework and .Net Core Denial of Service Vulnerability
vendor_msrc·2019-05-14·CVSS 7.5
CVE-2019-0981 [HIGH] .Net Framework and .Net Core Denial of Service Vulnerability
.Net Framework and .Net Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Framework or .NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Framework or .NET Core application.
The update addresses the vulnerability by correcting how .NET Framework or .NET Core web applications handles web requests.
.NET Core: .NET Core
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exp
Red Hat
dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0981 [HIGH] CWE-400 dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
GHSA
Denial of service in ASP.NET Core
ghsa·2022-05-24·CVSS 7.5
CVE-2019-0980 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
OSV
Denial of service in ASP.NET Core
osv·2022-05-24·CVSS 7.5
CVE-2019-0981 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
GHSA
Denial of service in ASP.NET Core
ghsa·2022-05-24·CVSS 7.5
CVE-2019-0981 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
OSV
Denial of service in ASP.NET Core
osv·2022-05-24·CVSS 7.5
CVE-2019-0980 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
GHSA
Regular Expression Denial of Service in System.Text.RegularExpressions
ghsa·2021-08-04·CVSS 7.5
CVE-2019-0820 [HIGH] CWE-1333 Regular Expression Denial of Service in System.Text.RegularExpressions
Regular Expression Denial of Service in System.Text.RegularExpressions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
OSV
Regular Expression Denial of Service in System.Text.RegularExpressions
osv·2021-08-04·CVSS 7.5
CVE-2019-0820 [HIGH] Regular Expression Denial of Service in System.Text.RegularExpressions
Regular Expression Denial of Service in System.Text.RegularExpressions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
No detection rules found.
No public exploits indexed.
2019-05-16
Published