Microsoft Microsoft.Netcore.App.Runtime.Linux-Arm vulnerabilities
31 known vulnerabilities affecting microsoft/microsoft.netcore.app.runtime.linux-arm.
Total CVEs
31
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
HIGH21MEDIUM10
Vulnerabilities
Page 1 of 2
CVE-2020-1147P1HIGHKEVPoC≥ 3.1.0, < 3.1.62022-05-24
CVE-2020-1147 [HIGH] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
ghsaosv
CVE-2026-26127P2HIGHCVSS 7.5Exploited≥ 9.0.0, < 9.0.14≥ 10.0.0, < 10.0.42026-03-11
CVE-2026-26127 [HIGH] CWE-125 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0 and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in .NE
ghsaosv
CVE-2025-21176P3HIGHCVSS 8.8≥ 9.0.0, < 9.0.1≥ 8.0.0, < 8.0.122025-01-14
CVE-2025-21176 [HIGH] CWE-126 Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory a
ghsaosv
CVE-2026-32178P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 9.0.0, < 9.0.15+1 more2026-04-14
CVE-2026-32178 [HIGH] CWE-138 Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
## Executive Summary:
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in System.Net.Mail where
ghsa
CVE-2020-36846P3MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-36846 [MEDIUM] Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streamin
osv
CVE-2026-50528P3HIGHCVSS 8.2≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-50528 [HIGH] CWE-302 Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A security feature
ghsa
CVE-2025-21172P3HIGHCVSS 7.5≥ >=6.0.0, ≤ 6.0.362025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
ghsanvdosv
CVE-2026-57108P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-57108 [HIGH] CWE-843 Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography layer (CryptoNative_GetX509NameInfo). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
ghsa
CVE-2026-50524P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-50524 [HIGH] CWE-1287 Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerabi
ghsa
CVE-2026-47302P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-47302 [HIGH] CWE-770 Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
ghsa
CVE-2026-50651P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-50651 [HIGH] CWE-770 Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerabil
ghsa
CVE-2026-26131P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.42026-03-11
CVE-2026-26131 [HIGH] CWE-276 .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An elevation of privilege vulnerability exist
ghsaosv
CVE-2025-30399P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.6≥ 8.0.0, < 8.0.172025-06-11
CVE-2025-30399 [HIGH] CWE-426 Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
# Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remo
ghsaosv
CVE-2023-24936P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7≥ 6.0.0, < 6.0.182023-06-14
CVE-2023-24936 [HIGH] .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
# Microsoft Security Advisory CVE-2023-24936: .NET Elevation of Privilege Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET when deseri
ghsaosv
CVE-2020-1108P3HIGH≥ 3.1.0, < 3.1.42022-05-24
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability
.NET Core & .NET Framework Denial of Service Vulnerability
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
ghsaosv
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.10≥ 9.0.0, < 9.0.18+1 more2026-07-20
CVE-2026-50659 [MEDIUM] CWE-116 Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A spoofing vulnerability exists in the SMTP cl
ghsa
CVE-2023-33128P3HIGHCVSS 7.3≥ 7.0.0, < 7.0.72023-06-14
CVE-2023-33128 [HIGH] CWE-416 .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
# Microsoft Security Advisory CVE-2023-33128: .NET Remote Code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET source generator fo
ghsaosv
CVE-2024-21392P3HIGHCVSS 7.5≥ 7.0.0-preview.1.22076.8, < 7.0.17≥ 8.0.0, < 8.0.32024-03-12
CVE-2024-21392 [HIGH] CWE-400 Microsoft Security Advisory CVE-2024-21392: .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2024-21392: .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2024-21392: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 8.0 . This advisory also provides guidance on what developers can do to update their appl
ghsaosv
CVE-2020-8927P3MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-8927 [MEDIUM] CWE-120 Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "s
ghsa
CVE-2024-30045P3MEDIUMCVSS 6.3≥ 7.0.0, < 7.0.19≥ 8.0.0, < 8.0.52024-05-14
CVE-2024-30045 [MEDIUM] CWE-122 Microsoft Security Advisory CVE-2024-30045 | .NET Remote code Execution Vulnerability
Microsoft Security Advisory CVE-2024-30045 | .NET Remote code Execution Vulnerability
# Microsoft Security Advisory CVE-2024-30045 | .NET Remote code Execution Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET. This advisory also provides guidance on what developers can do to update their appli
ghsaosv
1 / 2Next →