Microsoft Microsoft.Netcore.App.Runtime.Osx-X64 vulnerabilities

24 known vulnerabilities affecting microsoft/microsoft.netcore.app.runtime.osx-x64.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH16MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2020-1108HIGH≥ 3.1.0, < 3.1.42022-05-24
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability .NET Core & .NET Framework Denial of Service Vulnerability A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
ghsaosv
CVE-2021-1721MEDIUM≥ 3.1.0, < 3.1.12≥ 5.0.0, < 5.0.32022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core Denial of service in .NET core .NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
ghsaosv
CVE-2020-8927MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-8927 [MEDIUM] CWE-120 Integer overflow in the bundled Brotli C library Integer overflow in the bundled Brotli C library A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "s
ghsa
CVE-2020-36846MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-36846 [MEDIUM] Integer overflow in the bundled Brotli C library Integer overflow in the bundled Brotli C library A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streamin
osv