Page 7 of 307 results (0.008 seconds)

CVSS: 7.3EPSS: 1%CPEs: 6EXPL: 0

13 Jun 2023 — .NET and Visual Studio Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33135 •

CVSS: 7.3EPSS: 1%CPEs: 6EXPL: 0

13 Jun 2023 — .NET and Visual Studio Remote Code Execution Vulnerability A vulnerability was found in dotnet. This issue may allow remote code execution via source generators that can lead to a crash due to unmanaged heap corruption. .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.118 and .NET Runtime 6.0.18.... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33128 • CWE-416: Use After Free •

CVSS: 7.3EPSS: 1%CPEs: 6EXPL: 0

13 Jun 2023 — .NET and Visual Studio Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33126 •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

13 Jun 2023 — .NET and Visual Studio Elevation of Privilege Vulnerability A vulnerability was found in dotnet. This issue can cause an elevation of privilege when the TarFile.ExtractToDirectory ignores the extraction directory argument. .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 7.0.107 and .NET Runtime 7.0.... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32032 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

11 Apr 2023 — .NET DLL Hijacking Remote Code Execution Vulnerability It was discovered that .NET did not properly manage dll files. An attacker could potentially use this issue to execute arbitrary code. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28260 •

CVSS: 7.8EPSS: 1%CPEs: 96EXPL: 0

14 Feb 2023 — .NET and Visual Studio Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21808 • CWE-416: Use After Free •

CVSS: 5.0EPSS: 0%CPEs: 71EXPL: 0

14 Feb 2023 — .NET Framework Denial of Service Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21722 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

10 Jan 2023 — .NET Denial of Service Vulnerability Vulnerabilidad de denegación de servicio de .NET A vulnerability was found in dotnet. This flaw occurs when parsing an empty HTTP response as a JSON.NET JObject that causes a stack overflow and crashes a process. .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21538 • CWE-121: Stack-based Buffer Overflow CWE-502: Deserialization of Untrusted Data •

CVSS: 7.8EPSS: 8%CPEs: 62EXPL: 0

13 Dec 2022 — .NET Framework Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de .NET Framework. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41089 •

CVSS: 5.8EPSS: 0%CPEs: 76EXPL: 0

09 Nov 2022 — .NET Framework Information Disclosure Vulnerability Vulnerabilidad de divulgación de información de .NET Framework • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41064 •