Skip to content
Noroxi

mono-project records

7 published records for vendor mono-project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 23

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

7 records
  • The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

    CriticalCVSS 9.8No exploitEPSS 4%

    mono-project · monoJan 8, 2018

  • The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type

    HighCVSS 8.8No exploitEPSS 1%

    debian · debian linuxFeb 22, 2023

  • CVE-2015-2318
    33Monitor

    The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clie

    HighCVSS 8.1No exploitEPSS 2%

    mono-project · monoJan 8, 2018

  • CVE-2015-2319
    31Monitor

    The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via craft

    HighCVSS 7.5No exploitEPSS 3%

    mono-project · monoJan 8, 2018

  • CVE-2012-3543
    31Monitor

    mono 2.10.x ASP.NET Web Form Hash collision DoS

    HighCVSS 7.5No exploitEPSS 3%

    mono-project · monoNov 21, 2019

  • CVE-2010-1526
    28Monitor

    Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, rela

    MediumCVSS 6.8No exploitEPSS 2%

    mono-project · libgdiplusAug 24, 2010

  • CVE-2019-0757
    27Monitor

    A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet

    MediumCVSS 6.5No exploitEPSS 3%

    microsoft · visual studio 2017Apr 8, 2019