<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:32:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:0150 — Important: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:0150</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:0150</guid>
    </item>
    <item>
      <title>bdu:2024-00402</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00402</link>
      <description>bdu:2024-00402</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00402</guid>
    </item>
    <item>
      <title>BIT-dotnet-2024-0057 — NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-dotnet-2024-0057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-dotnet-2024-0057</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0022 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft .Net&lt;/span&gt;. Elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</link>
      <description>certfr-2024-avi-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-FM16465 — NET,</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-fm16465</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet6-build, CleanStart: dotnet6-runtime&lt;/p&gt;
&lt;p&gt;CVE-2024-0057 affects multiple packages. NET,. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet6-build, CleanStart: dotnet6-runtime&lt;/p&gt;
&lt;p&gt;CVE-2024-0057 affects multiple packages. NET,. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-fm16465</guid>
    </item>
    <item>
      <title>EUVD-2026-242685</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242685</link>
      <description>EUVD-2026-242685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242685</guid>
    </item>
    <item>
      <title>fkie_cve-2024-0057</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-0057</link>
      <description>&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-0057</guid>
    </item>
    <item>
      <title>GHSA-68w7-72jg-6qpp — NuGet Client Security Feature Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68w7-72jg-6qpp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: NuGet.CommandLine, NuGet: NuGet.Packaging&lt;/p&gt;
&lt;p&gt;### Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.&lt;/p&gt;
&lt;p&gt;A security feature bypass vulnerability exists when Microsoft .NET Framework-based applications use X.509 chain building APIs but do not completely validate the X.509 certificate due to a logic flaw. An attacker could present an arbitrary untrusted certificate with malformed signatures, triggering a bug in the framework. The framework will correctly report that X.509 chain building failed, but it will return an incorrect reason code for the failure. Applications which utilize this reason code to make their own chain building trust decisions may inadvertently treat this scenario as a successful chain build. This could allow an adversary to subvert the app&amp;#39;s typical authentication logic.&lt;/p&gt;
&lt;p&gt;### Affected software
#### NuGet &amp;amp; NuGet Packages
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.8.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.7.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.6.1 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.4.2 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.3.3 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.0.5 version or earlier. 
- Any NuGe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: NuGet.CommandLine, NuGet: NuGet.Packaging&lt;/p&gt;
&lt;p&gt;### Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 7.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.&lt;/p&gt;
&lt;p&gt;A security feature bypass vulnerability exists when Microsoft .NET Framework-based applications use X.509 chain building APIs but do not completely validate the X.509 certificate due to a logic flaw. An attacker could present an arbitrary untrusted certificate with malformed signatures, triggering a bug in the framework. The framework will correctly report that X.509 chain building failed, but it will return an incorrect reason code for the failure. Applications which utilize this reason code to make their own chain building trust decisions may inadvertently treat this scenario as a successful chain build. This could allow an adversary to subvert the app&amp;#39;s typical authentication logic.&lt;/p&gt;
&lt;p&gt;### Affected software
#### NuGet &amp;amp; NuGet Packages
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.8.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.7.0 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.6.1 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.4.2 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.3.3 version or earlier. 
- Any NuGet.exe, NuGet.CommandLine, NuGet.Packaging 6.0.5 version or earlier. 
- Any NuGe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68w7-72jg-6qpp</guid>
    </item>
    <item>
      <title>gsd-2024-0057</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-0057</link>
      <description>gsd-2024-0057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-0057</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-0057 — NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-0057</link>
      <description>msrc_CVE-2024-0057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-0057</guid>
    </item>
    <item>
      <title>RHSA-2024:0150 — Red Hat Security Advisory: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0150</link>
      <description>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0150</guid>
    </item>
    <item>
      <title>RHSA-2024:0255 — Red Hat Security Advisory: .NET 6.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0255</link>
      <description>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0255</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-0057</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7&lt;/p&gt;
&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7&lt;/p&gt;
&lt;p&gt;NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0057</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0039 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</guid>
    </item>
  </channel>
</rss>
