Microsoft.NetCore.App.Runtime.linux-arm64
NuGet16 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Microsoft.NetCore.App.Runtime.linux-arm64page 1 of 1
- CVE-2024-38095HIGHCVSS 7.5EG 7.5fixed in 8.0.7 or 6.0.32, by version range2024-07-09
vulnerable: 6.0.0 ... 6.0.9 (31 versions)
.NET and Visual Studio Denial of Service Vulnerability
- CVE-2024-38167MEDIUMCVSS 6.5EG 6.5fixed in 8.0.82024-08-13
vulnerable: 8.0.0 ... 8.0.7 (8 versions)
.NET and Visual Studio Information Disclosure Vulnerability
- CVE-2025-21171HIGHCVSS 7.5EG 7.5fixed in 9.0.12025-01-14
vulnerable: 9.0.0
.NET Remote Code Execution Vulnerability
- CVE-2025-21172HIGHCVSS 7.5EG 7.5fixed in 9.0.1 or 8.0.12, by version range2025-01-14
vulnerable: 8.0.0 ... 8.0.8 (11 versions)
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-21176HIGHCVSS 8.8EG 8.8fixed in 9.0.1 or 8.0.12, by version range2025-01-14
vulnerable: 8.0.0 ... 8.0.8 (11 versions)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-30399HIGHCVSS 7.5EG 7.5fixed in 9.0.6 or 8.0.17, by version range2025-06-13
vulnerable: 8.0.0 ... 8.0.8 (16 versions)
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2025-55248MEDIUMCVSS 4.8EG 4.8fixed in 9.0.10 or 8.0.21, by version range2025-10-14
vulnerable: 8.0.0 ... 8.0.8 (20 versions)
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- CVE-2026-26127HIGHCVSS 7.5EG 7.5fixed in 9.0.14 or 10.0.4, by version range2026-03-10
vulnerable: 10.0.0, 10.0.1, 10.0.2, 10.0.3
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-26131HIGHCVSS 7.8EG 7.8fixed in 10.0.42026-03-10
vulnerable: 10.0.0, 10.0.1, 10.0.2, 10.0.3
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2026-32178HIGHCVSS 7.5EG 7.5fixed in 10.0.6, 9.0.15 or 8.0.26, by version range2026-04-14
vulnerable: 8.0.0 ... 8.0.8 (25 versions)
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47302HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-50524HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-50528HIGHCVSS 8.2EG 8.2fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-50651HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-50659MEDIUMCVSS 6.5EG 6.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- CVE-2026-57108HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Check whether Microsoft.NetCore.App.Runtime.linux-arm64 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Microsoft.NetCore.App.Runtime.linux-arm64 CVEs against the assets you own.
Book a Demo →