CVE-2018-8171
- EPSS 11.5%
- Veröffentlicht 11.07.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:23
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, A...
CVE-2017-0249
- EPSS 5.79%
- Veröffentlicht 12.05.2017 14:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
CVE-2017-0256
- EPSS 4.35%
- Veröffentlicht 12.05.2017 14:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
CVE-2017-0247
- EPSS 11.12%
- Veröffentlicht 12.05.2017 14:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.We...
CVE-2014-4075
- EPSS 18.6%
- Veröffentlicht 15.10.2014 10:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."