CVE-2017-0256

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
microsoftasp.net_model_view_controller
1.0.0
microsoftasp.net_model_view_controller
1.0.1
microsoftasp.net_model_view_controller
1.0.2
microsoftasp.net_model_view_controller
1.0.3
microsoftasp.net_model_view_controller
1.1.0
microsoftasp.net_model_view_controller
1.1.1
microsoftasp.net_model_view_controller
1.1.2
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.0.0
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.0.1
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.0.2
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.0.3
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.1.0
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.1.1
microsoftmicrosoft.aspnetcore.mvc.abstractions
1.1.2
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.0.0
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.0.1
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.0.2
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.0.3
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.1.0
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.1.1
microsoftmicrosoft.aspnetcore.mvc.apiexplorer
1.1.2
microsoftmicrosoft.aspnetcore.mvc.cors
1.0.0
microsoftmicrosoft.aspnetcore.mvc.cors
1.0.1
microsoftmicrosoft.aspnetcore.mvc.cors
1.0.2
microsoftmicrosoft.aspnetcore.mvc.cors
1.0.3
microsoftmicrosoft.aspnetcore.mvc.cors
1.1.0
microsoftmicrosoft.aspnetcore.mvc.cors
1.1.1
microsoftmicrosoft.aspnetcore.mvc.cors
1.1.2
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.0.0
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.0.1
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.0.2
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.0.3
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.1.0
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.1.1
microsoftmicrosoft.aspnetcore.mvc.dataannotations
1.1.2
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.0.0
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.0.1
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.0.2
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.0.3
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.1.0
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.1.1
microsoftmicrosoft.aspnetcore.mvc.formatters.json
1.1.2
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.0.0
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.0.1
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.0.2
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.0.3
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.1.0
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.1.1
microsoftmicrosoft.aspnetcore.mvc.formatters.xml
1.1.2
microsoftmicrosoft.aspnetcore.mvc.localization
1.0.0
microsoftmicrosoft.aspnetcore.mvc.localization
1.0.1
microsoftmicrosoft.aspnetcore.mvc.localization
1.0.2
microsoftmicrosoft.aspnetcore.mvc.localization
1.0.3
microsoftmicrosoft.aspnetcore.mvc.localization
1.1.0
microsoftmicrosoft.aspnetcore.mvc.localization
1.1.1
microsoftmicrosoft.aspnetcore.mvc.localization
1.1.2
microsoftmicrosoft.aspnetcore.mvc.razor
1.0.0
microsoftmicrosoft.aspnetcore.mvc.razor
1.0.1
microsoftmicrosoft.aspnetcore.mvc.razor
1.0.2
microsoftmicrosoft.aspnetcore.mvc.razor
1.0.3
microsoftmicrosoft.aspnetcore.mvc.razor
1.1.0
microsoftmicrosoft.aspnetcore.mvc.razor
1.1.1
microsoftmicrosoft.aspnetcore.mvc.razor
1.1.2
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.0.0
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.0.1
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.0.2
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.0.3
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.1.0
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.1.1
microsoftmicrosoft.aspnetcore.mvc.razor.host
1.1.2
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.0.0
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.0.1
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.0.2
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.0.3
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.1.0
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.1.1
microsoftmicrosoft.aspnetcore.mvc.taghelpers
1.1.2
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.0.0
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.0.1
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.0.2
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.0.3
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.1.0
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.1.1
microsoftmicrosoft.aspnetcore.mvc.viewfeatures
1.1.2
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.0.0
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.0.1
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.0.2
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.0.3
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.1.0
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.1.1
microsoftmicrosoft.aspnetcore.mvc.webapicompatshim
1.1.2
microsoftsystem.net.http
4.1.1
microsoftsystem.net.http
4.3.1
microsoftsystem.net.http.winhttphandler
4.0.1
microsoftsystem.net.http.winhttphandler
4.3.0
microsoftsystem.net.security
4.0.0
microsoftsystem.net.security
4.3.0
microsoftsystem.net.websockets.client
4.0.0
microsoftsystem.net.websockets.client
4.3.0
microsoftsystem.text.encodings.web
4.0.0
microsoftsystem.text.encodings.web
4.3.0
𝑥
= Vulnerable software versions