Microsoft Microsoft.Netcore.App.Runtime.Win-Arm vulnerabilities

29 known vulnerabilities affecting microsoft/microsoft.netcore.app.runtime.win-arm.

Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH21MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2023-21538HIGHCVSS 7.5≥ 6.0.0, < 6.0.132023-01-10
CVE-2023-21538 [HIGH] CWE-502 .NET Denial of Service Vulnerability .NET Denial of Service Vulnerability # Microsoft Security Advisory CVE-2023-21538: .NET Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 6.0 where a m
ghsaosv
CVE-2021-26423HIGHCVSS 7.5≥ 3.1.0, < 3.1.18≥ 5.0.0, < 5.0.92022-10-25
CVE-2021-26423 [HIGH] .NET Core Elevation of Privilege Vulnerability .NET Core Elevation of Privilege Vulnerability Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where .NET (Core) server applications providing WebS
ghsaosv
CVE-2021-34485MEDIUMCVSS 5.5≥ 3.1.0, < 3.1.18≥ 5.0.0, < 5.0.92022-10-20
CVE-2021-34485 [MEDIUM] .NET Core Information Disclosure Vulnerability .NET Core Information Disclosure Vulnerability Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the too
ghsaosv
CVE-2022-24512MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-10-18
CVE-2022-24512 [MEDIUM] .NET Remote Code Execution Vulnerability .NET Remote Code Execution Vulnerability Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A Remote Code Execution vulnerability exists in .NET 6.0, .NET 5.0, and .NET Core 3.1 where a stack buffer overrun occurs in .NET Double P
ghsaosv
CVE-2020-1147HIGHKEVPoC≥ 3.1.0, < 3.1.62022-05-24
CVE-2020-1147 [HIGH] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
ghsaosv
CVE-2020-1108HIGH≥ 3.1.0, < 3.1.42022-05-24
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability .NET Core & .NET Framework Denial of Service Vulnerability A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
ghsaosv
CVE-2021-1721MEDIUM≥ 3.1.0, < 3.1.12≥ 5.0.0, < 5.0.32022-05-24
CVE-2021-1721 [MEDIUM] Denial of service in .NET core Denial of service in .NET core .NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building.
ghsaosv
CVE-2020-8927MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-8927 [MEDIUM] CWE-120 Integer overflow in the bundled Brotli C library Integer overflow in the bundled Brotli C library A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "s
ghsa
CVE-2020-36846MEDIUM≥ 3.0.0, < 3.1.23≥ 5.0.0, < 5.0.15+1 more2022-05-24
CVE-2020-36846 [MEDIUM] Integer overflow in the bundled Brotli C library Integer overflow in the bundled Brotli C library A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streamin
osv