Microsoft Corporation Asp.Net Core vulnerabilities

9 known vulnerabilities affecting microsoft_corporation/asp.net_core.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2018-0808HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-03-14
CVE-2018-0808 [HIGH] CVE-2018-0808: ASP ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.
cvelistv5
CVE-2018-0787HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-03-14
CVE-2018-0787 [HIGH] CWE-640 CVE-2018-0787: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applicat ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
cvelistv5nvd
CVE-2018-0784HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-01-10
CVE-2018-0784 [HIGH] CVE-2018-0784: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.
cvelistv5nvd
CVE-2018-0785MEDIUMCVSS 6.5vASP.NET Core 1.0. 1.1, and 2.02018-01-10
CVE-2018-0785 [MEDIUM] CWE-352 CVE-2018-0785: ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET C ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
cvelistv5nvd
CVE-2017-8700HIGHCVSS 7.5vASP.NET Core 1.0, 1.1, and 2.02017-11-15
CVE-2017-8700 [HIGH] CVE-2017-8700: ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) conf ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".
cvelistv5nvd
CVE-2017-11879HIGHCVSS 8.8vASP.NET Core 2.02017-11-15
CVE-2017-11879 [HIGH] CWE-601 CVE-2017-11879: ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentic ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
cvelistv5nvd
CVE-2017-0249HIGHCVSS 7.3vASP.NET Core2017-05-12
CVE-2017-0249 [HIGH] CWE-20 CVE-2017-0249: An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
cvelistv5nvd
CVE-2017-0247HIGHCVSS 7.5vASP.NET Core2017-05-12
CVE-2017-0247 [HIGH] CWE-20 CVE-2017-0247: A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web reques A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denia
cvelistv5nvd
CVE-2017-0256MEDIUMCVSS 5.3vASP.NET Core2017-05-12
CVE-2017-0256 [MEDIUM] CWE-20 CVE-2017-0256: A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
cvelistv5nvd