Page 2 of 58 results (0.002 seconds)

CVSS: 7.8EPSS: 1%CPEs: 47EXPL: 0

12 Sep 2023 — Visual Studio Remote Code Execution Vulnerability Vulnerabilidad de Ejecución Remota de Códigode Visual Studio • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36792 • CWE-190: Integer Overflow or Wraparound •

CVSS: 7.8EPSS: 1%CPEs: 48EXPL: 0

12 Sep 2023 — Visual Studio Remote Code Execution Vulnerability Vulnerabilidad de Ejecución Remota de Código de Visual Studio • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36793 • CWE-122: Heap-based Buffer Overflow •

CVSS: 7.8EPSS: 1%CPEs: 48EXPL: 0

12 Sep 2023 — Visual Studio Remote Code Execution Vulnerability Vulnerabilidad de Ejecución Remota de Código de Visual Studio • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36794 • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVSS: 7.8EPSS: 1%CPEs: 48EXPL: 0

12 Sep 2023 — Visual Studio Remote Code Execution Vulnerability Vulnerabilidad de Ejecución Remota de Código de Visual Studio • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36796 • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVSS: 7.8EPSS: 7%CPEs: 6EXPL: 0

12 Sep 2023 — .NET Core and Visual Studio Denial of Service Vulnerability Vulnerabilidad de Denegación de Servicio en .NET Core y Visual Studio A vulnerability was found in dotnet. This issue can lead to a denial of service when processing X.509 certificates. USN-6438-1 fixed vulnerabilities in .Net. It was discovered that the fix for [CVE-2023-36799] was incomplete. This update fixes the problem. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36799 • CWE-400: Uncontrolled Resource Consumption •

CVSS: 6.7EPSS: 1%CPEs: 5EXPL: 0

12 Sep 2023 — Visual Studio Elevation of Privilege Vulnerability Vulnerabilidad de Elevación de Privilegios en Visual Studio • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36759 • CWE-822: Untrusted Pointer Dereference •

CVSS: 7.8EPSS: 56%CPEs: 8EXPL: 0

08 Aug 2023 — .NET and Visual Studio Denial of Service Vulnerability An uncontrolled resource consumption vulnerability was found in the Kestrel component of the dotNET. When detecting a potentially malicious client, Kestrel will sometimes fail to disconnect it, resulting in denial of service. It was discovered that .NET did not properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. Benoit Foucher discovered that .NET did not properly implement the Q... • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V • CWE-400: Uncontrolled Resource Consumption •

CVSS: 7.8EPSS: 2%CPEs: 6EXPL: 0

08 Aug 2023 — ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35391 •

CVSS: 7.8EPSS: 10%CPEs: 3EXPL: 0

08 Aug 2023 — .NET Core and Visual Studio Denial of Service Vulnerability It was discovered that .NET did not properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. Benoit Foucher discovered that .NET did not properly implement the QUIC stream limit in HTTP/3. An attacker could possibly use this issue to cause a denial of service. It was discovered that .NET did not properly handle the disconnection of potentially malicious clients interfacing with a... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38178 • CWE-400: Uncontrolled Resource Consumption •

CVSS: 7.8EPSS: 8%CPEs: 5EXPL: 0

08 Aug 2023 — .NET and Visual Studio Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de .NET y Visual Studio A vulnerability was found in dotnet. This issue exists when some dotnet commands are used in directories with weaker permissions, which can result in remote code execution. It was discovered that .NET did not properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. Benoit Foucher discovered that .NET did not prop... • https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •