<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:03:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4450 — Important: dotnet8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4450</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: aspnetcore-runtime-8.0, AlmaLinux:9: aspnetcore-runtime-dbg-8.0, AlmaLinux:9: aspnetcore-targeting-pack-8.0, AlmaLinux:9: dotnet-apphost-pack-8.0, AlmaLinux:9: dotnet-host, AlmaLinux:9: dotnet-hostfxr-8.0, AlmaLinux:9: dotnet-runtime-8.0, AlmaLinux:9: dotnet-runtime-dbg-8.0, AlmaLinux:9: dotnet-sdk-8.0, AlmaLinux:9: dotnet-sdk-8.0-source-built-artifacts and 4 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: DoS in System.Text.Json (CVE-2024-30105)
* dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264)
* dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: aspnetcore-runtime-8.0, AlmaLinux:9: aspnetcore-runtime-dbg-8.0, AlmaLinux:9: aspnetcore-targeting-pack-8.0, AlmaLinux:9: dotnet-apphost-pack-8.0, AlmaLinux:9: dotnet-host, AlmaLinux:9: dotnet-hostfxr-8.0, AlmaLinux:9: dotnet-runtime-8.0, AlmaLinux:9: dotnet-runtime-dbg-8.0, AlmaLinux:9: dotnet-sdk-8.0, AlmaLinux:9: dotnet-sdk-8.0-source-built-artifacts and 4 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: DoS in System.Text.Json (CVE-2024-30105)
* dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264)
* dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4450</guid>
    </item>
    <item>
      <title>bdu:2024-05254</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05254</link>
      <description>bdu:2024-05254</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05254</guid>
    </item>
    <item>
      <title>BIT-dotnet-2024-30105 — .NET and Visual Studio Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-dotnet-2024-30105</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-dotnet-2024-30105</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0558 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0558</link>
      <description>certfr-2024-avi-0558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0558</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-GD81484 — .NET and Visual Studio Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-gd81484</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet8-runtime&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the dotnet8-runtime package. .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet8-runtime&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the dotnet8-runtime package. .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-gd81484</guid>
    </item>
    <item>
      <title>cnvd-2024-37491</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-37491</link>
      <description>cnvd-2024-37491</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-37491</guid>
    </item>
    <item>
      <title>EUVD-2026-263056</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263056</link>
      <description>EUVD-2026-263056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263056</guid>
    </item>
    <item>
      <title>fkie_cve-2024-30105</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-30105</link>
      <description>&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-30105</guid>
    </item>
    <item>
      <title>GHSA-hh2w-p6rv-4g7w — Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh2w-p6rv-4g7w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.Text.Json&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in  .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A vulnerability exists in .NET when calling the JsonSerializer.DeserializeAsyncEnumerable method against an untrusted input using System.Text.Json may result in Denial of Service.&lt;/p&gt;
&lt;p&gt;## Discussion&lt;/p&gt;
&lt;p&gt;Discussion for this issue can be found at  https://github.com/dotnet/runtime/issues/104619&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Microsoft has not identified any mitigating factors for this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any .NET 8.0 application running on .NET 8.0.6 or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 8&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 8
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[System.Text.Json](https://www.nuget.org/packages/System.Text.Json)               | &amp;gt;= 7.0.0, &amp;lt; =8.0.3 | 8.0.4&lt;/p&gt;
&lt;p&gt;## Advisory FAQ&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;how-affected&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;How do I know if I am affected?&lt;/p&gt;
&lt;p&gt;If you have a runtime or SDK with a version listed, or an affected package listed in [aff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.Text.Json&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in  .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A vulnerability exists in .NET when calling the JsonSerializer.DeserializeAsyncEnumerable method against an untrusted input using System.Text.Json may result in Denial of Service.&lt;/p&gt;
&lt;p&gt;## Discussion&lt;/p&gt;
&lt;p&gt;Discussion for this issue can be found at  https://github.com/dotnet/runtime/issues/104619&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Microsoft has not identified any mitigating factors for this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any .NET 8.0 application running on .NET 8.0.6 or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 8&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 8
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[System.Text.Json](https://www.nuget.org/packages/System.Text.Json)               | &amp;gt;= 7.0.0, &amp;lt; =8.0.3 | 8.0.4&lt;/p&gt;
&lt;p&gt;## Advisory FAQ&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;how-affected&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;How do I know if I am affected?&lt;/p&gt;
&lt;p&gt;If you have a runtime or SDK with a version listed, or an affected package listed in [aff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh2w-p6rv-4g7w</guid>
    </item>
    <item>
      <title>gsd-2024-30105</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-30105</link>
      <description>gsd-2024-30105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-30105</guid>
    </item>
    <item>
      <title>ICSA-25-100-02 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-100-02</link>
      <description>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-100-02</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-30105 — .NET and Visual Studio Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-30105</link>
      <description>msrc_CVE-2024-30105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-30105</guid>
    </item>
    <item>
      <title>RHSA-2024:4450 — Red Hat Security Advisory: dotnet8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4450</link>
      <description>&lt;p&gt;dotnet: DoS in System.Text.Json dotnet: DoS in ASP.NET Core 8 dotnet: DoS when parsing X.509 Content and ObjectIdentifiers&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: DoS in System.Text.Json dotnet: DoS in ASP.NET Core 8 dotnet: DoS when parsing X.509 Content and ObjectIdentifiers&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4450</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-30105</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-30105</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet8&lt;/p&gt;
&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet8&lt;/p&gt;
&lt;p&gt;.NET and Visual Studio Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-30105</guid>
    </item>
    <item>
      <title>VDE-2024-067 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Engineer</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-067</link>
      <description>&lt;p&gt;Vulnerabilities in .NET and Visual Studio functions System.Text.Json, System.Formats.Asn1, OPCFoundation.NetStandard.Opc.Ua.Core allow an remote attacker to execute a Denial-of-Servce attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerabilities in .NET and Visual Studio functions System.Text.Json, System.Formats.Asn1, OPCFoundation.NetStandard.Opc.Ua.Core allow an remote attacker to execute a Denial-of-Servce attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-067</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1560 — Microsoft .NET Framework: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1560</link>
      <description>&lt;p&gt;Ein lokaler oder ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Microsoft .NET Framework und Microsoft Visual Studio 2022 ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen und eine Denial-of-Service-Situation zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Microsoft .NET Framework und Microsoft Visual Studio 2022 ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen und eine Denial-of-Service-Situation zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1560</guid>
    </item>
  </channel>
</rss>
