Copilot
84 exploits
Active since Feb 2025
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVSS 4.4
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVSS 6.5
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVSS 6.2
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVSS 3.7
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVSS 10.0
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVSS 7.4
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVSS 7.5
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVSS 5.9
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVSS 4.4
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVSS 6.5
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVSS 6.2
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVSS 3.7
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVSS 10.0
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVSS 7.4
gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVSS 7.8