| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. |
| An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.
To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.
The update addresses the vulnerability by correcting how .NET Framework activates COM objects. |
| .NET and Visual Studio Remote Code Execution Vulnerability |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. |
| Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. |