← Back

.net

Vendor: Microsoft • 104 CVEs

CVEs (104)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4.net
.net CoreMono+1 more
Jun 17, 2026
Feb 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
.NET Core Remote Code Execution Vulnerability
1Microsoft
5.net
.net CorePowershell Core+2 more
Jun 17, 2026
Feb 25, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
.NET Core and Visual Studio Denial of Service Vulnerability
6Canonical
DebianFedoraproject+3 more
10.net
.net CoreBrotli+7 more
Jun 17, 2026
Sep 15, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over...Show more
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.Show less
1Microsoft
7.net
.net Core.net Framework+4 more
Aug 19, 2026
May 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or...Show more
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.Show less