Записи mono
21 опубликованных записей вендора mono.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 52,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-12471Эксплойта нет | MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because ofmono · monox · CWE-502 | Критическая9,8 | — | 2,8 % | 29 апр. 2020 г. |
34Наблюдать | CVE-2010-4254Proof of concept | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allowmono · mono · CWE-20 | Высокая7,5 | — | 13,6 % | 6 дек. 2010 г. |
31Наблюдать | CVE-2007-5197Эксплойта нет | Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code vmono · mono · CWE-119 | Высокая7,5 | — | 3,6 % | 2 нояб. 2007 г. |
29Наблюдать | CVE-2020-12470Эксплойта нет | MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.mono · monox · CWE-552 | Высокая7,2 | — | 1,7 % | 29 апр. 2020 г. |
28Наблюдать | CVE-2011-0991Эксплойта нет | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a deniamono · mono · CWE-399 | Средняя6,8 | — | 2,9 % | 13 апр. 2011 г. |
28Наблюдать | CVE-2020-12473Эксплойта нет | MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to amono · monox | Высокая7,2 | — | 1,4 % | 29 апр. 2020 г. |
27Наблюдать | CVE-2010-4159Эксплойта нет | Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shmono · mono | Средняя6,9 | — | 0,4 % | 17 нояб. 2010 г. |
24Наблюдать | CVE-2011-0992Эксплойта нет | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a deniamono · mono · CWE-399 | Средняя5,8 | — | 2,7 % | 13 апр. 2011 г. |
24Наблюдать | CVE-2011-0989Эксплойта нет | The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does nomono · mono · CWE-264 | Средняя5,8 | — | 2,7 % | 13 апр. 2011 г. |
24Наблюдать | CVE-2011-0990Эксплойта нет | Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x befmono · mono · CWE-362 | Средняя5,8 | — | 2,2 % | 13 апр. 2011 г. |
24Наблюдать | CVE-2006-5072Эксплойта нет | The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite amono · mono | Средняя6,2 | — | 0,5 % | 10 окт. 2006 г. |
22Наблюдать | CVE-2005-0509Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbimono · mono | Средняя4,3 | — | 15,9 % | 14 мар. 2005 г. |
22Наблюдать | CVE-2006-6104Proof of concept | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attmono · xsp | Средняя5,0 | — | 5,2 % | 21 дек. 2006 г. |
21Наблюдать | CVE-2006-2658Эксплойта нет | Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE mono · xsp | Средняя5,0 | — | 3,9 % | 12 сент. 2006 г. |
21Наблюдать | CVE-2020-12472Эксплойта нет | MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.mono · monox · CWE-79 | Средняя5,4 | — | 0,5 % | 29 апр. 2020 г. |
20Наблюдать | CVE-2010-4225Эксплойта нет | Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .amono · mono · CWE-200 | Средняя5,0 | — | 1,5 % | 10 янв. 2011 г. |
20Наблюдать | CVE-2007-5473Эксплойта нет | StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitimono · mono · CWE-200 | Средняя5,0 | — | 1,3 % | 18 окт. 2007 г. |
19Наблюдать | CVE-2008-3906Proof of concept | CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP remono · mono · CWE-20 | Средняя4,3 | — | 7,1 % | 4 сент. 2008 г. |
18Наблюдать | CVE-2010-1459Эксплойта нет | The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attamono · mono · CWE-79 | Средняя4,3 | — | 1,9 % | 27 мая 2010 г. |
18Наблюдать | CVE-2012-3382Эксплойта нет | Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2mono · mono · CWE-79 | Средняя4,3 | — | 1,9 % | 12 июл. 2012 г. |
17Наблюдать | CVE-2008-3422Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject mono · mono · CWE-79 | Средняя4,3 | — | 1,6 % | 31 июл. 2008 г. |
- CVE-2020-1247140В плане
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mono · monox29 апр. 2020 г.
- CVE-2010-425434Наблюдать
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allow
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %mono · mono6 дек. 2010 г.
- CVE-2007-519731Наблюдать
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code v
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mono · mono2 нояб. 2007 г.
- CVE-2020-1247029Наблюдать
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %mono · monox29 апр. 2020 г.
- CVE-2011-099128Наблюдать
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denia
СредняяCVSS 6,8Эксплойта нетEPSS 3 %mono · mono13 апр. 2011 г.
- CVE-2020-1247328Наблюдать
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %mono · monox29 апр. 2020 г.
- CVE-2010-415927Наблюдать
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse sh
СредняяCVSS 6,9Эксплойта нетEPSS 0 %mono · mono17 нояб. 2010 г.
- CVE-2011-099224Наблюдать
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denia
СредняяCVSS 5,8Эксплойта нетEPSS 3 %mono · mono13 апр. 2011 г.
- CVE-2011-098924Наблюдать
The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does no
СредняяCVSS 5,8Эксплойта нетEPSS 3 %mono · mono13 апр. 2011 г.
- CVE-2011-099024Наблюдать
Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x bef
СредняяCVSS 5,8Эксплойта нетEPSS 2 %mono · mono13 апр. 2011 г.
- CVE-2006-507224Наблюдать
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite a
СредняяCVSS 6,2Эксплойта нетEPSS 0 %mono · mono10 окт. 2006 г.
- CVE-2005-050922Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbi
СредняяCVSS 4,3Эксплойта нетEPSS 16 %mono · mono14 мар. 2005 г.
- CVE-2006-610422Наблюдать
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote att
СредняяCVSS 5,0Proof of conceptEPSS 5 %mono · xsp21 дек. 2006 г.
- CVE-2006-265821Наблюдать
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE
СредняяCVSS 5,0Эксплойта нетEPSS 4 %mono · xsp12 сент. 2006 г.
- CVE-2020-1247221Наблюдать
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %mono · monox29 апр. 2020 г.
- CVE-2010-422520Наблюдать
Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .a
СредняяCVSS 5,0Эксплойта нетEPSS 1 %mono · mono10 янв. 2011 г.
- CVE-2007-547320Наблюдать
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensiti
СредняяCVSS 5,0Эксплойта нетEPSS 1 %mono · mono18 окт. 2007 г.
- CVE-2008-390619Наблюдать
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP re
СредняяCVSS 4,3Proof of conceptEPSS 7 %mono · mono4 сент. 2008 г.
- CVE-2010-145918Наблюдать
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote atta
СредняяCVSS 4,3Эксплойта нетEPSS 2 %mono · mono27 мая 2010 г.
- CVE-2012-338218Наблюдать
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2
СредняяCVSS 4,3Эксплойта нетEPSS 2 %mono · mono12 июл. 2012 г.
- CVE-2008-342217Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject
СредняяCVSS 4,3Эксплойта нетEPSS 2 %mono · mono31 июл. 2008 г.