| CVE ID | Publié | Description | Score | Gravité |
|---|---|---|---|---|
| Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 6.7 |
Moyen |
||
| Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | 9.9 |
Critique |
||
| Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 5.7 |
Moyen |
||
| Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 7.3 |
Haute |
||
| Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | 7.8 |
Haute |
||
| Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 8.8 |
Haute |
||
| Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network. | 7.1 |
Haute |