mono-project records
7 published records for vendor mono-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-2320No exploit | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.mono-project · mono · CWE-295 | Critical9.8 | — | 3.5% | Jan 8, 2018 |
35Monitor | CVE-2023-26314No exploit | The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type debian · debian linux | High8.8 | — | 1.0% | Feb 22, 2023 |
33Monitor | CVE-2015-2318No exploit | The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate cliemono-project · mono · CWE-295 | High8.1 | — | 2.0% | Jan 8, 2018 |
31Monitor | CVE-2015-2319No exploit | The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via craftmono-project · mono · CWE-295 | High7.5 | — | 3.2% | Jan 8, 2018 |
31Monitor | CVE-2012-3543No exploit | mono 2.10.x ASP.NET Web Form Hash collision DoSmono-project · mono · CWE-20 | High7.5 | — | 2.6% | Nov 21, 2019 |
28Monitor | CVE-2010-1526No exploit | Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, relamono-project · libgdiplus · CWE-189 | Medium6.8 | — | 1.9% | Aug 24, 2010 |
27Monitor | CVE-2019-0757No exploit | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGetmicrosoft · visual studio 2017 | Medium6.5 | — | 2.7% | Apr 8, 2019 |
- CVE-2015-232040Plan
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
CriticalCVSS 9.8No exploitEPSS 4%mono-project · monoJan 8, 2018
- CVE-2023-2631435Monitor
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type
HighCVSS 8.8No exploitEPSS 1%debian · debian linuxFeb 22, 2023
- CVE-2015-231833Monitor
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clie
HighCVSS 8.1No exploitEPSS 2%mono-project · monoJan 8, 2018
- CVE-2015-231931Monitor
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via craft
HighCVSS 7.5No exploitEPSS 3%mono-project · monoJan 8, 2018
- CVE-2012-354331Monitor
mono 2.10.x ASP.NET Web Form Hash collision DoS
HighCVSS 7.5No exploitEPSS 3%mono-project · monoNov 21, 2019
- CVE-2010-152628Monitor
Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, rela
MediumCVSS 6.8No exploitEPSS 2%mono-project · libgdiplusAug 24, 2010
- CVE-2019-075727Monitor
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet
MediumCVSS 6.5No exploitEPSS 3%microsoft · visual studio 2017Apr 8, 2019