Filtered by vendor Microsoft Subscriptions
Filtered by product Powershell Subscriptions
Total 39 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-38095 2 Microsoft, Redhat 5 .net, Powershell, Visual Studio and 2 more 2024-09-19 7.5 High
.NET and Visual Studio Denial of Service Vulnerability
CVE-2024-30105 2 Microsoft, Redhat 5 .net, Powershell, Visual Studio and 2 more 2024-09-19 7.5 High
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2020-8927 7 Canonical, Debian, Fedoraproject and 4 more 12 Ubuntu Linux, Debian Linux, Fedora and 9 more 2024-08-04 5.3 Medium
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
CVE-2020-1108 2 Microsoft, Redhat 17 .net, .net Core, .net Framework and 14 more 2024-08-04 7.5 High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
CVE-2020-0951 1 Microsoft 12 Powershell, Powershell Core, Windows 10 and 9 more 2024-08-04 6.7 Medium
<p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code.</p> <p>The update addresses the vulnerability by correcting how PowerShell commands are validated when WDAC protection is enabled.</p>
CVE-2021-43896 1 Microsoft 2 Cbl Mariner, Powershell 2024-08-04 5.5 Medium
Microsoft PowerShell Spoofing Vulnerability
CVE-2021-41355 2 Microsoft, Redhat 6 .net, Powershell, Powershell Core and 3 more 2024-08-04 5.7 Medium
.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2022-41121 1 Microsoft 24 Powershell, Remote Desktop, Windows 10 and 21 more 2024-08-03 7.8 High
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2022-41076 1 Microsoft 23 Powershell, Windows 10, Windows 10 1507 and 20 more 2024-08-03 8.5 High
PowerShell Remote Code Execution Vulnerability
CVE-2022-41089 1 Microsoft 16 .net, .net Core, .net Framework and 13 more 2024-08-03 7.8 High
.NET Framework Remote Code Execution Vulnerability
CVE-2022-34716 2 Microsoft, Redhat 9 .net, .net Core, Powershell and 6 more 2024-08-03 5.9 Medium
.NET Spoofing Vulnerability
CVE-2022-26788 1 Microsoft 22 Powershell, Powershell Core, Windows 10 and 19 more 2024-08-03 7.8 High
PowerShell Elevation of Privilege Vulnerability
CVE-2022-24512 3 Fedoraproject, Microsoft, Redhat 9 Fedora, .net, .net Core and 6 more 2024-08-03 6.3 Medium
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2022-23267 3 Fedoraproject, Microsoft, Redhat 9 Fedora, .net, .net Core and 6 more 2024-08-03 7.5 High
.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-48795 43 9bis, Apache, Apple and 40 more 78 Kitty, Sshd, Sshj and 75 more 2024-08-02 5.9 Medium
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
CVE-2023-38171 1 Microsoft 8 .net, Powershell, Visual Studio and 5 more 2024-08-02 7.5 High
Microsoft QUIC Denial of Service Vulnerability
CVE-2023-36792 1 Microsoft 18 .net, .net Framework, Powershell and 15 more 2024-08-02 7.8 High
Visual Studio Remote Code Execution Vulnerability
CVE-2023-36793 1 Microsoft 18 .net, .net Framework, Powershell and 15 more 2024-08-02 7.8 High
Visual Studio Remote Code Execution Vulnerability
CVE-2023-36799 2 Microsoft, Redhat 6 .net, Powershell, Visual Studio and 3 more 2024-08-02 6.5 Medium
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-36796 1 Microsoft 18 .net, .net Framework, Powershell and 15 more 2024-08-02 7.8 High
Visual Studio Remote Code Execution Vulnerability