| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| .NET Core and Visual Studio Information Disclosure Vulnerability |
| ASP.NET Core Denial of Service Vulnerability |
| .NET and Visual Studio Elevation of Privilege Vulnerability |
| Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability |
| Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability |
| Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability |
| Visual Studio Remote Code Execution Vulnerability |
| .NET Core Remote Code Execution Vulnerability |
| Visual Studio Elevation of Privilege Vulnerability |
| .NET Core and Visual Studio Denial of Service Vulnerability |
| .NET Core Remote Code Execution Vulnerability |
| ASP.NET Core and Visual Studio Denial of Service Vulnerability |
| .NET Core and Visual Studio Denial of Service Vulnerability |
| Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
| Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
| Visual Studio Code Remote Code Execution Vulnerability |
| A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits. |
| Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. |
| An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. |
| An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418. |