5.3

CVE-2017-0256

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Abstractions Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Apiexplorer Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Cors Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Dataannotations Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Json Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Formatters.Xml Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Localization Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Razor.Host Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Taghelpers Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Viewfeatures Version1.1.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.0.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.0.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.0.2 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.0.3 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.1.0 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.1.1 SwPlatformasp.net
MicrosoftMicrosoft.Aspnetcore.Mvc.Webapicompatshim Version1.1.2 SwPlatformasp.net
MicrosoftSystem.Net.Http Version4.1.1 SwPlatformasp.net
MicrosoftSystem.Net.Http Version4.3.1 SwPlatformasp.net
MicrosoftSystem.Net.Http.Winhttphandler Version4.0.1 SwPlatformasp.net
MicrosoftSystem.Net.Http.Winhttphandler Version4.3.0 SwPlatformasp.net
MicrosoftSystem.Net.Security Version4.0.0 SwPlatformasp.net
MicrosoftSystem.Net.Security Version4.3.0 SwPlatformasp.net
MicrosoftSystem.Net.Websockets.Client Version4.0.0 SwPlatformasp.net
MicrosoftSystem.Net.Websockets.Client Version4.3.0 SwPlatformasp.net
MicrosoftSystem.Text.Encodings.Web Version4.0.0 SwPlatformasp.net
MicrosoftSystem.Text.Encodings.Web Version4.3.0 SwPlatformasp.net
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.35% 0.878
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.