CyberShieldTips
Best Of
How-To Guides
Password Managers
Privacy Tools
Threat Analysis
VPN Reviews
📚 Resources
☰
Home
›
CVE Database
›
Microsoft
›
CVE-2022-38013
CVE-2022-38013
.NET Core and Visual Studio Denial of Service Vulnerability
high
7.5
CVSS 3.1
Published:
Sep 13, 2022
Modified:
May 27, 2026
Vendor:
Microsoft
Product:
.Net
Versions:
6.0.0,3.1,16.9,16.11,17.0,17.2,17.3,35,36,37
Description
.NET Core and Visual Studio Denial of Service Vulnerability
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38013
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2CUL3Z7MEED7RFQZVGQL2MTKSFFZKAAY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HCV4TQGOTOFHO5ETRKGFKAGYV2YAUVE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JA6F4CDKLI3MALV6UK3P2DR5AGCLTT7Y/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4K5YL7USOKIR3O2DUKBZMYPWXYPDKXG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL334CKOHA6BQQSYJW365HIWJ4IOE45M/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-38013
Related CVEs
CVE-2026-49940
medium · 6.5
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parse
CVE-2026-49941
high · 7.5
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmas
CVE-2026-49942
high · 7.3
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661)
CVE-2026-46739
medium · 5.3
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could i
CVE-2026-8722
medium · 6.5
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untruste
CVE-2026-45584
high · 8.1
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.