Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2017-0247

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

CWEs:

Software From Fixed in
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.cors 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.localization 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.cors 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.1.1 1.1.1.x
microsoft / system.net.security 4.0.0 4.0.0.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.0.2 1.0.2.x
microsoft / system.text.encodings.web 4.0.0 4.0.0.x
microsoft / microsoft.aspnetcore.mvc.razor 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.localization 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.razor 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.1.1 1.1.1.x
microsoft / system.net.websockets.client 4.0.0 4.0.0.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.0.1 1.0.1.x
microsoft / system.net.security 4.3.0 4.3.0.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.cors 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.localization 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.cors 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.cors 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.localization 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.0.1 1.0.1.x
microsoft / system.net.http.winhttphandler 4.0.1 4.0.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.razor 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.1.2 1.1.2.x
microsoft / system.net.http 4.3.1 4.3.1.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.1.1 1.1.1.x
microsoft / system.net.websockets.client 4.3.0 4.3.0.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.localization 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.razor 1.0.2 1.0.2.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.dataannotations 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.localization 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor 1.1.2 1.1.2.x
microsoft / microsoft.aspnetcore.mvc.formatters.xml 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.apiexplorer 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.webapicompatshim 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor 1.0.1 1.0.1.x
microsoft / microsoft.aspnetcore.mvc.formatters.json 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.0.3 1.0.3.x
microsoft / system.text.encodings.web 4.3.0 4.3.0.x
microsoft / microsoft.aspnetcore.mvc.abstractions 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.localization 1.1.2 1.1.2.x
microsoft / system.net.http 4.1.1 4.1.1.x
microsoft / microsoft.aspnetcore.mvc.cors 1.1.1 1.1.1.x
microsoft / system.net.http.winhttphandler 4.3.0 4.3.0.x
microsoft / microsoft.aspnetcore.mvc.cors 1.0.3 1.0.3.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.0.0 1.0.0.x
microsoft / microsoft.aspnetcore.mvc.viewfeatures 1.1.0 1.1.0.x
microsoft / microsoft.aspnetcore.mvc.razor.host 1.1.1 1.1.1.x
microsoft / microsoft.aspnetcore.mvc.taghelpers 1.1.1 1.1.1.x
microsoft / asp.net_model_view_controller 1.1.1 1.1.1.x
microsoft / asp.net_model_view_controller 1.1.0 1.1.0.x
microsoft / asp.net_model_view_controller 1.1.2 1.1.2.x
microsoft / asp.net_model_view_controller 1.0.1 1.0.1.x
microsoft / asp.net_model_view_controller 1.0.0 1.0.0.x
microsoft / asp.net_model_view_controller 1.0.3 1.0.3.x
microsoft / asp.net_model_view_controller 1.0.2 1.0.2.x
Microsoft.AspNetCore.Mvc 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Core 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Core 1.1.0 1.1.3
System.Net.Http 4.1.1 4.1.1.x
System.Net.Http 4.1.1 4.1.2
System.Net.Http 4.3.1 4.3.1.x
System.Net.Http 4.3.1 4.3.2
System.Text.Encodings.Web 4.0.0 4.0.0.x
System.Text.Encodings.Web 4.0.0 4.0.1
System.Text.Encodings.Web 4.3.0 4.3.0.x
System.Text.Encodings.Web 4.3.0 4.3.1
System.Net.Http.WinHttpHandler 4.0.0 4.0.0.x
System.Net.Http.WinHttpHandler 4.0.0 4.0.1
System.Net.Http.WinHttpHandler 4.3.0 4.5.4
System.Net.Security 4.0.0 4.0.0.x
System.Net.Security 4.0.0 4.0.1
System.Net.Security 4.3.0 4.3.0.x
System.Net.Security 4.3.0 4.3.1
System.Net.WebSockets.Client 4.0.0 4.0.0.x
System.Net.WebSockets.Client 4.0.0 4.0.1
System.Net.WebSockets.Client 4.3.0 4.3.0.x
System.Net.WebSockets.Client 4.3.0 4.3.1
Microsoft.AspNetCore.Mvc.Abstractions 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Abstractions 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.ApiExplorer 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.ApiExplorer 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Cors 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Cors 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.DataAnnotations 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.DataAnnotations 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Formatters.Json 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Formatters.Json 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Formatters.Xml 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Formatters.Xml 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Localization 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Localization 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Razor.Host 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Razor.Host 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.Razor 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.Razor 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.TagHelpers 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.TagHelpers 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.ViewFeatures 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.ViewFeatures 1.1.0 1.1.3
Microsoft.AspNetCore.Mvc.WebApiCompatShim 1.0.0 1.0.4
Microsoft.AspNetCore.Mvc.WebApiCompatShim 1.1.0 1.1.3