<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:21:36.681452+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0150</id>
    <title>ALSA-2024:0150 — Important: .NET 8.0 security update</title>
    <updated>2026-10-04T00:21:36.988168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.</p>
<p>Security Fix(es):</p>
<p>* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00642</id>
    <title>bdu:2024-00642</title>
    <updated>2026-10-04T00:21:36.988251+00:00</updated>
    <content>bdu:2024-00642</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2024-21319</id>
    <title>BIT-dotnet-2024-21319 — Microsoft Identity Denial of service vulnerability</title>
    <updated>2026-10-04T00:21:36.988269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>Microsoft Identity Denial of service vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2024-21319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</id>
    <title>certfr-2024-avi-0022 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft .Net&lt;/span&gt;. Elles permettent à un at…</title>
    <updated>2026-10-04T00:21:36.988288+00:00</updated>
    <content>certfr-2024-avi-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-ww90034</id>
    <title>CLEANSTART-2025-WW90034 — Microsoft Identity Denial of service vulnerability</title>
    <updated>2026-10-04T00:21:36.988304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: dotnet6-build, CleanStart: dotnet6-runtime</p>
<p>CVE-2024-21319 affects multiple packages. Microsoft Identity Denial of service vulnerability See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-ww90034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-242679</id>
    <title>EUVD-2026-242679</title>
    <updated>2026-10-04T00:21:36.988325+00:00</updated>
    <content>EUVD-2026-242679</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-242679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21319</id>
    <title>fkie_cve-2024-21319</title>
    <updated>2026-10-04T00:21:36.988337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Microsoft Identity Denial of service vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-21319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-59j7-ghrg-fj52</id>
    <title>GHSA-59j7-ghrg-fj52 — Microsoft ASP.NET Core project templates vulnerable to denial of service</title>
    <updated>2026-10-04T00:21:36.988356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: System.IdentityModel.Tokens.Jwt, NuGet: Microsoft.IdentityModel.JsonWebTokens</p>
<p>A Denial of Service vulnerability exists in ASP.NET Core project templates which utilize JWT-based authentication tokens. This vulnerability allows an unauthenticated client to consume arbitrarily large amounts of server memory, potentially triggering an out-of-memory condition on the server and making the server no longer able to respond to legitimate requests.</p>
<p>## Announcement</p>
<p>Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/290</p>
<p>### Mitigation factors</p>
<p>This impacts only .NET Core-based projects that were created using any version of project templates listed in affected software. 
Other project templates e.g., console applications, MAUI applications, Windows Forms or WPF applications, are not affected.</p>
<p>## Affected software</p>
<p>This impacts only .NET Core-based projects that were created using any version of the below project templates.</p>
<p>-	ASP.NET Core Web App (Model-View-Controller)
-	ASP.NET Core Web API
-	ASP.NET Core Web App (Razor Pages)
-	Blazor Server App
-	Blazor WebAssembly App</p>
<p>## Advisory FAQ</p>
<p>### How do I know if I am affected?</p>
<p>If you are you using project templates listed in affected software, you may be exposed to the vulnerability.</p>
<p>### How do I fix the issue?</p>
<p>#### For existing projects:
If you ever created any of these projects via the dotnet new command or via Visual Studio's File -&gt; New Project gesture, and if you enabled federated authentication at project creation time, your project may be vulnerable. To remed…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-59j7-ghrg-fj52"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-21319</id>
    <title>gsd-2024-21319</title>
    <updated>2026-10-04T00:21:36.988419+00:00</updated>
    <content>gsd-2024-21319</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-21319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-100-02</id>
    <title>ICSA-25-100-02 — Siemens SIDIS Prime</title>
    <updated>2026-10-04T00:21:36.988431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-100-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-21319</id>
    <title>msrc_CVE-2024-21319 — Microsoft Identity Denial of service vulnerability</title>
    <updated>2026-10-04T00:21:36.988523+00:00</updated>
    <content>msrc_CVE-2024-21319</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-21319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0150</id>
    <title>RHSA-2024:0150 — Red Hat Security Advisory: .NET 8.0 security update</title>
    <updated>2026-10-04T00:21:36.988540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0255</id>
    <title>RHSA-2024:0255 — Red Hat Security Advisory: .NET 6.0 security, bug fix, and enhancement update</title>
    <updated>2026-10-04T00:21:36.988561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: Information Disclosure: MD.SqlClient(MDS) &amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21319</id>
    <title>UBUNTU-CVE-2024-21319</title>
    <updated>2026-10-04T00:21:36.988579+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7</p>
<p>Microsoft Identity Denial of service vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</id>
    <title>WID-SEC-W-2024-0039 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:21:36.988598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039"/>
  </entry>
</feed>
