<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:56:13.597847+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0150</id>
    <title>ALSA-2024:0150 — Important: .NET 8.0 security update</title>
    <updated>2026-10-03T10:56:13.908491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.</p>
<p>Security Fix(es):</p>
<p>* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00402</id>
    <title>bdu:2024-00402</title>
    <updated>2026-10-03T10:56:13.908620+00:00</updated>
    <content>bdu:2024-00402</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2024-0057</id>
    <title>BIT-dotnet-2024-0057 — NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</title>
    <updated>2026-10-03T10:56:13.908644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2024-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</id>
    <title>certfr-2024-avi-0022 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft .Net&lt;/span&gt;. Elles permettent à un at…</title>
    <updated>2026-10-03T10:56:13.908676+00:00</updated>
    <content>certfr-2024-avi-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-fm16465</id>
    <title>CLEANSTART-2025-FM16465 — NET,</title>
    <updated>2026-10-03T10:56:13.908702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: dotnet6-build, CleanStart: dotnet6-runtime</p>
<p>CVE-2024-0057 affects multiple packages. NET,. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-fm16465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-242685</id>
    <title>EUVD-2026-242685</title>
    <updated>2026-10-03T10:56:13.908736+00:00</updated>
    <content>EUVD-2026-242685</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-242685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-0057</id>
    <title>fkie_cve-2024-0057</title>
    <updated>2026-10-03T10:56:13.908755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-68w7-72jg-6qpp</id>
    <title>GHSA-68w7-72jg-6qpp — NuGet Client Security Feature Bypass Vulnerability</title>
    <updated>2026-10-03T10:56:13.908785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: NuGet.CommandLine, NuGet: NuGet.Packaging</p>
<p>### Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.</p>
<p>A security feature bypass vulnerability exists when Microsoft .NET Framework-based applications use X.509 chain building APIs but do not completely validate the X.509 certificate due to a logic flaw. An attacker could present an arbitrary untrusted certificate with malformed signatures, triggering a bug in the framework. The framework will correctly report that X.509 chain building failed, but it will return an incorrect reason code for the failure. Applications which utilize this reason code to make their own chain building trust decisions may inadvertently treat this scenario as a successful chain build. This could allow an adversary to subvert the app's typical authentication logic.</p>
<p>### Affected software
#### NuGet &amp; NuGet Packages
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.8.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.7.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.6.1 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.4.2 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.3.3 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.0.5 version or earlier. 
- Any NuGe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-68w7-72jg-6qpp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-0057</id>
    <title>gsd-2024-0057</title>
    <updated>2026-10-03T10:56:13.908938+00:00</updated>
    <content>gsd-2024-0057</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-0057</id>
    <title>msrc_CVE-2024-0057 — NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</title>
    <updated>2026-10-03T10:56:13.908957+00:00</updated>
    <content>msrc_CVE-2024-0057</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0150</id>
    <title>RHSA-2024:0150 — Red Hat Security Advisory: .NET 8.0 security update</title>
    <updated>2026-10-03T10:56:13.908985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0255</id>
    <title>RHSA-2024:0255 — Red Hat Security Advisory: .NET 6.0 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T10:56:13.909019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0057</id>
    <title>UBUNTU-CVE-2024-0057</title>
    <updated>2026-10-03T10:56:13.909053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7</p>
<p>NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</id>
    <title>WID-SEC-W-2024-0039 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:56:13.909083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039"/>
  </entry>
</feed>
