Microsoft Corporation Asp.Net Core vulnerabilities
9 known vulnerabilities affecting microsoft_corporation/asp.net_core.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-0808HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-03-14
CVE-2018-0808 [HIGH] CVE-2018-0808: ASP
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.
cvelistv5
CVE-2018-0787HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-03-14
CVE-2018-0787 [HIGH] CWE-640 CVE-2018-0787: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applicat
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
cvelistv5nvd
CVE-2018-0784HIGHCVSS 8.8vASP.NET Core 1.0. 1.1, and 2.02018-01-10
CVE-2018-0784 [HIGH] CVE-2018-0784: ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.
cvelistv5nvd
CVE-2018-0785MEDIUMCVSS 6.5vASP.NET Core 1.0. 1.1, and 2.02018-01-10
CVE-2018-0785 [MEDIUM] CWE-352 CVE-2018-0785: ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET C
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
cvelistv5nvd
CVE-2017-8700HIGHCVSS 7.5vASP.NET Core 1.0, 1.1, and 2.02017-11-15
CVE-2017-8700 [HIGH] CVE-2017-8700: ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) conf
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".
cvelistv5nvd
CVE-2017-11879HIGHCVSS 8.8vASP.NET Core 2.02017-11-15
CVE-2017-11879 [HIGH] CWE-601 CVE-2017-11879: ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentic
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
cvelistv5nvd
CVE-2017-0249HIGHCVSS 7.3vASP.NET Core2017-05-12
CVE-2017-0249 [HIGH] CWE-20 CVE-2017-0249: An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
cvelistv5nvd
CVE-2017-0247HIGHCVSS 7.5vASP.NET Core2017-05-12
CVE-2017-0247 [HIGH] CWE-20 CVE-2017-0247: A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web reques
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denia
cvelistv5nvd
CVE-2017-0256MEDIUMCVSS 5.3vASP.NET Core2017-05-12
CVE-2017-0256 [MEDIUM] CWE-20 CVE-2017-0256: A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
cvelistv5nvd