Microsoft.NetCore.App.Runtime.win-x86
NuGet20 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Microsoft.NetCore.App.Runtime.win-x86page 1 of 1
- CVE-2023-21808HIGHCVSS 7.8EG 7.8fixed in 7.0.3 or 6.0.14, by version range2023-02-14
vulnerable: 6.0.0 ... 6.0.9 (14 versions)
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-24897HIGHCVSS 7.8EG 7.8fixed in 7.0.7 or 6.0.18, by version range2023-06-14
vulnerable: 6.0.0 ... 6.0.9 (17 versions)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-28260HIGHCVSS 7.8EG 7.8fixed in 7.0.5 or 6.0.16, by version range2023-04-11
vulnerable: 6.0.0 ... 6.0.9 (16 versions)
.NET DLL Hijacking Remote Code Execution Vulnerability
- CVE-2023-33126HIGHCVSS 7.3EG 7.3fixed in 6.0.18 or 7.0.7, by version range2023-06-14
vulnerable: 7.0.0 ... 7.0.5 (6 versions)
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-38178HIGHCVSS 7.5EG 7.5fixed in 7.0.102023-08-08
vulnerable: 7.0.0 ... 7.0.9 (9 versions)
.NET Core and Visual Studio Denial of Service Vulnerability
- CVE-2024-38095HIGHCVSS 7.5EG 7.5fixed in 6.0.32 or 8.0.7, by version range2024-07-09
vulnerable: 8.0.0 ... 8.0.6 (7 versions)
.NET and Visual Studio Denial of Service Vulnerability
- CVE-2024-38167MEDIUMCVSS 6.5EG 6.5fixed in 8.0.82024-08-13
vulnerable: 8.0.0 ... 8.0.7 (8 versions)
.NET and Visual Studio Information Disclosure Vulnerability
- CVE-2025-21171HIGHCVSS 7.5EG 7.5fixed in 9.0.12025-01-14
vulnerable: 9.0.0
.NET Remote Code Execution Vulnerability
- CVE-2025-21172HIGHCVSS 7.5EG 7.5fixed in 9.0.12025-01-14
vulnerable: 9.0.0
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-21176HIGHCVSS 8.8EG 8.8fixed in 9.0.1 or 8.0.12, by version range2025-01-14
vulnerable: 8.0.0 ... 8.0.8 (11 versions)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-30399HIGHCVSS 7.5EG 7.5fixed in 9.0.6 or 8.0.17, by version range2025-06-13
vulnerable: 8.0.0 ... 8.0.8 (16 versions)
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2025-55248MEDIUMCVSS 4.8EG 4.8fixed in 9.0.10 or 8.0.21, by version range2025-10-14
vulnerable: 8.0.0 ... 8.0.8 (20 versions)
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- CVE-2026-26127HIGHCVSS 7.5EG 7.5fixed in 9.0.14 or 10.0.4, by version range2026-03-10
vulnerable: 10.0.0, 10.0.1, 10.0.2, 10.0.3
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-32175MEDIUMCVSS 4.3EG 4.3fixed in 8.0.27, 9.0.16 or 10.0.8, by version range2026-05-12
vulnerable: 10.0.0 ... 10.0.7 (8 versions)
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. …
- CVE-2026-32178HIGHCVSS 7.5EG 7.5fixed in 10.0.6, 9.0.15 or 8.0.26, by version range2026-04-14
vulnerable: 8.0.0 ... 8.0.8 (25 versions)
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47302HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-50524HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-50528HIGHCVSS 8.2EG 8.2fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-50651HIGHCVSS 7.5EG 7.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-50659MEDIUMCVSS 6.5EG 6.5fixed in 10.0.10, 9.0.18 or 8.0.29, by version range2026-07-14
vulnerable: 8.0.0 ... 8.0.8 (28 versions)
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Check whether Microsoft.NetCore.App.Runtime.win-x86 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Microsoft.NetCore.App.Runtime.win-x86 CVEs against the assets you own.
Book a Demo →