Vulnerabilities
Vulnerable Software
.NET and Visual Studio Elevation of Privilege Vulnerability
CVSS Score
7.3
EPSS Score
0.087
Published
2021-05-11
Visual Studio Remote Code Execution Vulnerability
CVSS Score
8.8
EPSS Score
0.077
Published
2021-05-11
.NET Core Remote Code Execution Vulnerability
CVSS Score
8.1
EPSS Score
0.017
Published
2021-02-25
Visual Studio Code Remote Code Execution Vulnerability
CVSS Score
7.0
EPSS Score
0.013
Published
2021-02-25
.NET Core and Visual Studio Denial of Service Vulnerability
CVSS Score
6.5
EPSS Score
0.07
Published
2021-02-25
ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVSS Score
7.5
EPSS Score
0.034
Published
2021-01-12
Visual Studio Remote Code Execution Vulnerability
CVSS Score
7.8
EPSS Score
0.063
Published
2020-12-10
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
CVSS Score
5.3
EPSS Score
0.004
Published
2020-09-15
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles data operations.</p>
CVSS Score
6.6
EPSS Score
0.007
Published
2020-09-11
<p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploit this vulnerability by running a specially crafted application on the victim system.</p> <p>The update addresses the vulnerability by correcting the way the Diagnostics Hub Standard Collector handles file operations.</p>
CVSS Score
5.5
EPSS Score
0.008
Published
2020-09-11


Contact Us

Shodan ® - All rights reserved