Vulnerabilities
Vulnerable Software
Microsoft:  >> .net  Security Vulnerabilities
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
CVSS Score
6.2
EPSS Score
0.004
Published
2026-06-09
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.024
Published
2026-05-12
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.007
Published
2026-05-12
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
CVSS Score
4.3
EPSS Score
0.007
Published
2026-05-12
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.006
Published
2026-05-12
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.021
Published
2026-04-14
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.016
Published
2026-04-14
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
7.5
EPSS Score
0.023
Published
2026-04-14
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.018
Published
2026-04-14
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
CVSS Score
7.5
EPSS Score
0.03
Published
2026-03-19


Contact Us

Shodan ® - All rights reserved