Microsoft System.Text.Encodings.Web vulnerabilities
5 known vulnerabilities affecting microsoft/system.text.encodings.web.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-26701CRITICALCVSS 9.8≥ 4.0.0, < 4.5.1≥ 4.6.0, < 4.7.2+1 more2021-04-21
CVE-2021-26701 [CRITICAL] .NET Core Remote Code Execution Vulnerability
.NET Core Remote Code Execution Vulnerability
.NET Core Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24112.
### Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1, and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A remot
ghsaosv
CVE-2017-0248MEDIUM≥ 4.0.0, < 4.0.1≥ 4.3.0, < 4.3.12018-10-16
CVE-2017-0248 [MEDIUM] CWE-295 Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
ghsaosv
CVE-2017-0247HIGHCVSS 7.5v4.0.0v4.3.02017-05-12
CVE-2017-0247 [HIGH] CWE-20 CVE-2017-0247: A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web reques
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denia
ghsanvdosv
CVE-2017-0249HIGHCVSS 7.3v4.0.0v4.3.02017-05-12
CVE-2017-0249 [HIGH] CWE-20 CVE-2017-0249: An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ghsanvdosv
CVE-2017-0256MEDIUMCVSS 5.3v4.0.0v4.3.02017-05-12
CVE-2017-0256 [MEDIUM] CWE-20 CVE-2017-0256: A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ghsanvdosv