Microsoft Microsoft.Aspnetcore.App.Runtime.Linux-Arm vulnerabilities
24 known vulnerabilities affecting microsoft/microsoft.aspnetcore.app.runtime.linux-arm.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM3
Vulnerabilities
Page 1 of 2
CVE-2025-55315P1CRITICALCVSS 9.9PoC≥ 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107≥ 9.0.0, < 9.0.10+1 more2025-10-14
CVE-2025-55315 [CRITICAL] CWE-444 Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 10.0 , ASP.NET Core 9.0 , ASP.NET Core 8.0, and ASP.NET Core 2.3. This a
ghsaosv
CVE-2020-0603P2HIGH≥ 3.1.0, < 3.1.12022-05-24
CVE-2020-0603 [HIGH] CWE-119 Remote code execution in ASP.NET Core
Remote code execution in ASP.NET Core
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
ghsaosv
CVE-2024-35264P3HIGHCVSS 8.1≥ 8.0.0, < 8.0.72024-07-09
CVE-2024-35264 [HIGH] CWE-416 Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their app
ghsaosv
CVE-2024-38229P3HIGHCVSS 8.1≥ >=6.0.0, ≤ 6.0.362024-10-08
CVE-2024-38229 [HIGH] CWE-416 CVE-2024-38229: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
ghsanvdosv
CVE-2026-26130P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.25≥ 9.0.0, < 9.0.14+1 more2026-03-11
CVE-2026-26130 [HIGH] CWE-770 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2026-26130 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability ex
ghsaosv
CVE-2023-33170P3HIGHCVSS 8.1≥ 0, < 6.0.20≥ 7.0.0, < 7.0.92023-07-11
CVE-2023-33170 [HIGH] CWE-362 Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can d
ghsaosv
CVE-2026-42899P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-18
CVE-2026-42899 [HIGH] CWE-835 Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
## Executive Summary:
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Loop with unre
ghsa
CVE-2026-56170P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 9.0.0, < 9.0.15+1 more2026-07-21
CVE-2026-56170 [HIGH] CWE-770 Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR (Microsoft.AspNetCore.App.Runtime). This advisory also provides guidance on what de
ghsa
CVE-2020-1597P3HIGH≥ 3.1.0, < 3.1.72022-05-24
CVE-2020-1597 [HIGH] CWE-20 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka `ASP.NET Core Denial of Service Vulnerability`.
ghsaosv
CVE-2025-24070P3HIGHCVSS 7.0≥ 9.0.0, < 9.0.3≥ 8.0.0, < 8.0.14+1 more2025-03-11
CVE-2025-24070 [HIGH] CWE-1390 Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 9.0, ASP.NET Core 8.0, ASP.NET Core 6.0, and ASP.NET Core 2.3. This advisory a
ghsaosv
CVE-2020-1045P3HIGH≥ 3.1.0, < 3.1.82022-05-24
CVE-2020-1045 [HIGH] Cookie parsing failure
Cookie parsing failure
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Featur
ghsaosv
CVE-2025-7326P3HIGHCVSS 7.0≥ >=6.0.0, ≤ 6.0.362025-07-08
CVE-2025-7326 [HIGH] CWE-1390 CVE-2025-7326: Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
nvd
CVE-2022-23267P3HIGHCVSS 7.5≥ 3.0.0, < 3.1.25≥ 5.0.0, < 5.0.17+1 more2022-10-21
CVE-2022-23267 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET Core 3.1 where a malicious client can cause a Denial of Service via excess memory allo
ghsaosv
CVE-2020-0602P3MEDIUM≥ 3.1.0, < 3.1.12022-05-24
CVE-2020-0602 [MEDIUM] CWE-400 Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ghsaosv
CVE-2020-1161P3HIGH≥ 3.1.0, < 3.1.42022-05-24
CVE-2020-1161 [HIGH] CWE-20 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ghsaosv
CVE-2022-29117P3HIGH≥ 3.0.0, < 3.1.25≥ 5.0.0, < 5.0.17+1 more2022-08-30
CVE-2022-29117 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET core 3.1 where a malicious client can manipulate cookies and cause a Denial of Service
ghsaosv
CVE-2022-29145P3HIGH≥ 3.0.0, < 3.1.25≥ 5.0.0, < 5.0.17+1 more2022-08-30
CVE-2022-29145 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET core 3.1 where a malicious client can can cause a denial of service when HTML forms are parsed
ghsaosv
CVE-2021-1723P3HIGH≥ 3.1.0, < 3.1.11≥ 5.0.0, < 5.0.22022-05-24
CVE-2021-1723 [HIGH] ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
ghsaosv
CVE-2022-24464P3HIGH≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-10-21
CVE-2022-24464 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET CORE 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Microsoft is aware of a Denial of Service vulnerability, which exists in .NET 6.0, .NET 5.0, and .NET CORE 3.1 when parsing certain types of http f
ghsaosv
CVE-2022-38013P3HIGH≥ 3.1.0, < 3.1.29≥ 5.0.0, < 6.0.92022-09-15
CVE-2022-38013 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in ASP.NET Core 3.1 and .NET 6.0 where a malicious client could cause a stack overflow which may result in a denial o
ghsaosv
1 / 2Next →