monkey-project records
29 published records for vendor monkey-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.4%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-125 Out-of-bounds Read5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-416 Use After Free2
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2013-2159No exploit | Monkey HTTP Daemon: broken user name authenticationmonkey-project · monkey · CWE-287 | Critical9.8 | — | 2.8% | Dec 10, 2019 |
33Monitor | CVE-2013-3843Weaponized | Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remonkey-project · monkey · CWE-119 | Medium6.8 | — | 20.2% | Jun 13, 2014 |
33Monitor | CVE-2025-63655No exploit | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Demonkey-project · monkey · CWE-476 | High7.5 | — | 8.6% | Jan 29, 2026 |
32Monitor | CVE-2003-0218No exploit | Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary codmonkey-project · monkey · CWE-119 | High7.5 | — | 5.2% | May 12, 2003 |
31Monitor | CVE-2013-1771No exploit | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.monkey-project · monkey · CWE-532 | High7.5 | — | 3.0% | Nov 7, 2019 |
31Monitor | CVE-2005-1122No exploit | Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possimonkey-project · monkey · CWE-134 | High7.5 | — | 2.7% | Apr 14, 2005 |
30Monitor | CVE-2025-63658No exploit | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Smonkey-project · monkey · CWE-121 | High7.5 | — | 1.3% | Jan 29, 2026 |
30Monitor | CVE-2025-63656No exploit | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial ofmonkey-project · monkey · CWE-125 | High7.5 | — | 1.2% | Jan 29, 2026 |
30Monitor | CVE-2025-63650No exploit | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-125 | High7.5 | — | 1.2% | Jan 29, 2026 |
30Monitor | CVE-2025-63652No exploit | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Semonkey-project · monkey · CWE-416 | High7.5 | — | 1.2% | Jan 29, 2026 |
30Monitor | CVE-2025-63653No exploit | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial monkey-project · monkey · CWE-125 | High7.5 | — | 1.2% | Jan 29, 2026 |
30Monitor | CVE-2025-63657No exploit | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denialmonkey-project · monkey · CWE-125 | High7.5 | — | 1.2% | Jan 29, 2026 |
30Monitor | CVE-2025-63649No exploit | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attmonkey-project · monkey · CWE-125 | High7.5 | — | 1.1% | Jan 29, 2026 |
30Monitor | CVE-2025-63651No exploit | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-416 | High7.5 | — | 1.1% | Jan 29, 2026 |
28Monitor | CVE-2013-2183No exploit | Monkey HTTP Daemon has local security bypassmonkey-project · monkey · CWE-668 | High7.1 | — | 0.4% | Dec 10, 2019 |
27Monitor | CVE-2012-4443No exploit | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gamonkey-project · monkey · CWE-264 | Medium6.9 | — | 0.4% | Oct 5, 2012 |
27Monitor | CVE-2012-5303No exploit | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathnmonkey-project · monkey · CWE-59 | Medium6.9 | — | 0.3% | Oct 5, 2012 |
25Monitor | CVE-2013-2182Proof of concept | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a craftedmonkey-project · monkey · CWE-264 | Medium5.8 | — | 5.6% | Jun 13, 2014 |
24Monitor | CVE-2013-3724Proof of concept | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash anmonkey-project · monkey · CWE-20 | Medium5.0 | — | 13.7% | Aug 1, 2013 |
22Monitor | CVE-2002-2154Proof of concept | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..monkey-project · monkey · CWE-22 | Medium5.0 | — | 7.6% | Dec 31, 2002 |
21Monitor | CVE-2002-1663Proof of concept | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a monkey-project · monkey · CWE-20 | Medium5.0 | — | 4.0% | Dec 31, 2002 |
21Monitor | CVE-2004-0276Proof of concept | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) monkey-project · monkey · CWE-20 | Medium5.0 | — | 3.7% | Nov 23, 2004 |
21Monitor | CVE-2013-2163No exploit | Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fimonkey-project · monkey · CWE-20 | Medium5.0 | — | 2.5% | Jun 13, 2014 |
21Monitor | CVE-2003-1209No exploit | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request monkey-project · monkey · CWE-20 | Medium5.0 | — | 2.4% | Dec 31, 2003 |
20Monitor | CVE-2005-1123No exploit | Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte monkey-project · monkey · CWE-119 | Medium5.0 | — | 1.6% | May 2, 2005 |
- CVE-2013-215940Plan
Monkey HTTP Daemon: broken user name authentication
CriticalCVSS 9.8No exploitEPSS 3%monkey-project · monkeyDec 10, 2019
- CVE-2013-384333Monitor
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows re
MediumCVSS 6.8WeaponizedEPSS 20%monkey-project · monkeyJun 13, 2014
- CVE-2025-6365533Monitor
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a De
HighCVSS 7.5No exploitEPSS 9%monkey-project · monkeyJan 29, 2026
- CVE-2003-021832Monitor
Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary cod
HighCVSS 7.5No exploitEPSS 5%monkey-project · monkeyMay 12, 2003
- CVE-2013-177131Monitor
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
HighCVSS 7.5No exploitEPSS 3%monkey-project · monkeyNov 7, 2019
- CVE-2005-112231Monitor
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possi
HighCVSS 7.5No exploitEPSS 3%monkey-project · monkeyApr 14, 2005
- CVE-2025-6365830Monitor
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of S
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365630Monitor
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365030Monitor
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365230Monitor
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Se
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365330Monitor
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365730Monitor
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6364930Monitor
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows att
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2025-6365130Monitor
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of
HighCVSS 7.5No exploitEPSS 1%monkey-project · monkeyJan 29, 2026
- CVE-2013-218328Monitor
Monkey HTTP Daemon has local security bypass
HighCVSS 7.1No exploitEPSS 0%monkey-project · monkeyDec 10, 2019
- CVE-2012-444327Monitor
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to ga
MediumCVSS 6.9No exploitEPSS 0%monkey-project · monkeyOct 5, 2012
- CVE-2012-530327Monitor
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathn
MediumCVSS 6.9No exploitEPSS 0%monkey-project · monkeyOct 5, 2012
- CVE-2013-218225Monitor
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted
MediumCVSS 5.8Proof of conceptEPSS 6%monkey-project · monkeyJun 13, 2014
- CVE-2013-372424Monitor
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash an
MediumCVSS 5.0Proof of conceptEPSS 14%monkey-project · monkeyAug 1, 2013
- CVE-2002-215422Monitor
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..
MediumCVSS 5.0Proof of conceptEPSS 8%monkey-project · monkeyDec 31, 2002
- CVE-2002-166321Monitor
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a
MediumCVSS 5.0Proof of conceptEPSS 4%monkey-project · monkeyDec 31, 2002
- CVE-2004-027621Monitor
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash)
MediumCVSS 5.0Proof of conceptEPSS 4%monkey-project · monkeyNov 23, 2004
- CVE-2013-216321Monitor
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fi
MediumCVSS 5.0No exploitEPSS 3%monkey-project · monkeyJun 13, 2014
- CVE-2003-120921Monitor
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request
MediumCVSS 5.0No exploitEPSS 2%monkey-project · monkeyDec 31, 2003
- CVE-2005-112320Monitor
Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte
MediumCVSS 5.0No exploitEPSS 2%monkey-project · monkeyMay 2, 2005