VYPR
Vendor

Mono

Products
10
CVEs
30
Across products
41
Status
Private

Products

10

Recent CVEs

30
View all 30 CVEs →
  • CVE-2020-12471CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.03

    MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.

  • CVE-2023-26314HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.01

    The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

  • CVE-2015-2320CriJan 8, 2018
    risk 0.57cvss 9.8epss 0.04

    The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

  • CVE-2020-12470HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.02

    MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

  • CVE-2020-12473HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.01

    MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

  • CVE-2015-2318HigJan 8, 2018
    risk 0.46cvss 8.1epss 0.02

    The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

  • CVE-2012-3543HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.03

    mono 2.10.x ASP.NET Web Form Hash collision DoS

  • CVE-2019-0757MedApr 9, 2019
    risk 0.42cvss 6.5epss 0.03

    A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.

  • CVE-2015-2319HigJan 8, 2018
    risk 0.42cvss 7.5epss 0.03

    The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

  • CVE-2020-12472MedApr 29, 2020
    risk 0.35cvss 5.4epss 0.01

    MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.

  • CVE-2008-3906Sep 4, 2008
    risk 0.04cvss epss 0.07

    CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

  • CVE-2006-6104Dec 21, 2006
    risk 0.03cvss epss 0.05

    The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

  • CVE-2005-0509Mar 14, 2005
    risk 0.01cvss epss 0.16

    Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters,…

  • CVE-2012-3382Jul 12, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension,…

  • CVE-2011-0992Apr 13, 2011
    risk 0.00cvss epss 0.03

    Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.

  • CVE-2011-0991Apr 13, 2011
    risk 0.00cvss epss 0.03

    Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.

  • CVE-2011-0990Apr 13, 2011
    risk 0.00cvss epss 0.02

    Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service…

  • CVE-2011-0989Apr 13, 2011
    risk 0.00cvss epss 0.03

    The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service…

  • CVE-2010-4225Jan 11, 2011
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug."

  • CVE-2010-4254Dec 6, 2010
    risk 0.00cvss epss 0.14

    Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.