Microsoft Microsoft.Aspnetcore.App.Runtime.Win-Arm vulnerabilities
25 known vulnerabilities affecting microsoft/microsoft.aspnetcore.app.runtime.win-arm.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH21MEDIUM3
Vulnerabilities
Page 2 of 2
CVE-2021-1723HIGH≥ 3.1.0, < 3.1.11≥ 5.0.0, < 5.0.22022-05-24
CVE-2021-1723 [HIGH] ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
ghsaosv
CVE-2020-0603HIGH≥ 3.1.0, < 3.1.12022-05-24
CVE-2020-0603 [HIGH] CWE-119 Remote code execution in ASP.NET Core
Remote code execution in ASP.NET Core
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
ghsaosv
CVE-2020-1597HIGH≥ 3.1.0, < 3.1.72022-05-24
CVE-2020-1597 [HIGH] CWE-20 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka `ASP.NET Core Denial of Service Vulnerability`.
ghsaosv
CVE-2020-1045HIGH≥ 3.1.0, < 3.1.82022-05-24
CVE-2020-1045 [HIGH] Cookie parsing failure
Cookie parsing failure
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Featur
ghsaosv
CVE-2020-0602MEDIUM≥ 3.1.0, < 3.1.12022-05-24
CVE-2020-0602 [MEDIUM] CWE-400 Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ghsaosv
← Previous2 / 2