5
CVSSv2

CVE-2017-0247

Published: 12/05/2017 Updated: 30/06/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc prior to 1.0.4 and 1.1.x prior to 1.1.3 allows remote malicious users to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft asp.net model view controller 1.1.0

microsoft asp.net model view controller 1.1.1

microsoft asp.net model view controller 1.1.2

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.0

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.2

microsoft asp.net model view controller 1.0.0

microsoft asp.net model view controller 1.0.1

microsoft asp.net model view controller 1.0.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.3

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.0

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.2

microsoft microsoft.aspnetcore.mvc.localization 1.0.0

microsoft microsoft.aspnetcore.mvc.localization 1.0.1

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.0

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.1

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.2

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.3

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.3

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.1

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.2

microsoft system.net.websockets.client 4.0.0

microsoft system.net.websockets.client 4.3.0

microsoft system.text.encodings.web 4.0.0

microsoft system.text.encodings.web 4.3.0

microsoft asp.net model view controller 1.0.3

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.3

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.3

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.1

microsoft microsoft.aspnetcore.mvc.cors 1.0.0

microsoft microsoft.aspnetcore.mvc.cors 1.1.1

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.2

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.2

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.0

microsoft microsoft.aspnetcore.mvc.localization 1.0.2

microsoft microsoft.aspnetcore.mvc.localization 1.1.0

microsoft microsoft.aspnetcore.mvc.razor 1.1.0

microsoft microsoft.aspnetcore.mvc.razor 1.1.2

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.1

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.2

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.3

microsoft system.net.http.winhttphandler 4.3.0

microsoft system.net.security 4.3.0

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.0

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.1

microsoft microsoft.aspnetcore.mvc.cors 1.0.1

microsoft microsoft.aspnetcore.mvc.cors 1.0.2

microsoft microsoft.aspnetcore.mvc.cors 1.0.3

microsoft microsoft.aspnetcore.mvc.cors 1.1.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.3

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.2

microsoft microsoft.aspnetcore.mvc.localization 1.1.2

microsoft microsoft.aspnetcore.mvc.razor 1.0.0

microsoft microsoft.aspnetcore.mvc.razor 1.0.1

microsoft microsoft.aspnetcore.mvc.razor 1.0.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.3

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.0

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.0

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.2

microsoft system.net.http 4.1.1

microsoft system.net.http 4.3.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.2

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.0

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.0

microsoft microsoft.aspnetcore.mvc.cors 1.1.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.1

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.2

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.3

microsoft microsoft.aspnetcore.mvc.localization 1.0.3

microsoft microsoft.aspnetcore.mvc.localization 1.1.1

microsoft microsoft.aspnetcore.mvc.razor 1.0.3

microsoft microsoft.aspnetcore.mvc.razor 1.1.1

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.1

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.2

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.0

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.2

microsoft system.net.http.winhttphandler 4.0.1

microsoft system.net.security 4.0.0

Github Repositories

NET Source Build Reference Packages This repository contains tools, source and build scripts for source buildable reference versions of historical NET Core packages that are referenced by NET source build These are used only when source building NET This repo supports three package types: Reference - A package that contains API signatures, no implementation It enables d