NuGet Package Vulnerabilities
Vulnerabilities associated with Microsoft.AspNetCore.App.
Packages
Clear package- Microsoft.ChakraCore247 vulnerabilities
- Magick.NET-Q16-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-AnyCPU163 vulnerabilities
- Magick.NET-Q8-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-x86162 vulnerabilities
- Magick.NET-Q16-x86161 vulnerabilities
- Magick.NET-Q8-x86161 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-x64159 vulnerabilities
- Magick.NET-Q16-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-OpenMP-x64159 vulnerabilities
- Magick.NET-Q16-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-arm64158 vulnerabilities
- Magick.NET-Q8-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-x64155 vulnerabilities
- Magick.NET-Q16-x64154 vulnerabilities
- Magick.NET-Q8-x64152 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-x6495 vulnerabilities
- Magick.NET-Q16-OpenMP-x8667 vulnerabilities
- DotNetNuke.Core36 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x6427 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x8626 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-arm25 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.linux-x6424 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-1045HIGH | Microsoft ASP.NET Core Security Feature Bypass VulnerabilityA security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Sep 11, 2020 | CVSS7.5v3.1 | EPSS5.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1597HIGH | ASP.NET Core Denial of Service VulnerabilityA denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka `ASP.NET Core Denial of Service Vulnerability`. CWE-20Aug 17, 2020 | CVSS7.5v3.1 | EPSS6.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0603HIGH | Remote code execution in ASP.NET CoreA remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. | CVSS8.8v3.1 | EPSS19.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0602HIGH | Denial of service in ASP.NET CoreA denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. CWE-400Jan 14, 2020 | CVSS7.5v3.1 | EPSS7.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-1075MEDIUM | Open redirect in ASP.NET CoreA spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. CWE-601Jul 15, 2019 | CVSS6.1v3.0 | EPSS2.64% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0564HIGH | Denial of service in ASP.NET CoreA denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. CWE-19Jan 8, 2019 | CVSS7.5v3.0 | EPSS8.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Moderate severity vulnerability that affects Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, and Microsoft.AspNetCore.Server.Kestrel.CoreMicrosoft is aware of a denial of service vulnerability in ASP.NET Core when a malformed request is terminated. An attacker who successfully exploited this vulnerability could cause a denial of service attack. The update addresses the vulnerability by correcting how ASP.NET Core handles such requests. Oct 16, 2018 | CVSS- | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2018-8409HIGH | Denial of service vulnerability exists when System.IO.Pipelines improperly handles requestsA denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. Sep 13, 2018 | CVSS7.5v3.1 | EPSS6.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |