Skip to content
Noroxi

monkey-project records

29 published records for vendor monkey-project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 3.4%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

29 records
  • Monkey HTTP Daemon: broken user name authentication

    CriticalCVSS 9.8No exploitEPSS 3%

    monkey-project · monkeyDec 10, 2019

  • CVE-2013-3843
    33Monitor

    Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows re

    MediumCVSS 6.8WeaponizedEPSS 20%

    monkey-project · monkeyJun 13, 2014

  • A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a De

    HighCVSS 7.5No exploitEPSS 9%

    monkey-project · monkeyJan 29, 2026

  • CVE-2003-0218
    32Monitor

    Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary cod

    HighCVSS 7.5No exploitEPSS 5%

    monkey-project · monkeyMay 12, 2003

  • CVE-2013-1771
    31Monitor

    The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.

    HighCVSS 7.5No exploitEPSS 3%

    monkey-project · monkeyNov 7, 2019

  • CVE-2005-1122
    31Monitor

    Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possi

    HighCVSS 7.5No exploitEPSS 3%

    monkey-project · monkeyApr 14, 2005

  • A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of S

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Se

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows att

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of

    HighCVSS 7.5No exploitEPSS 1%

    monkey-project · monkeyJan 29, 2026

  • CVE-2013-2183
    28Monitor

    Monkey HTTP Daemon has local security bypass

    HighCVSS 7.1No exploitEPSS 0%

    monkey-project · monkeyDec 10, 2019

  • CVE-2012-4443
    27Monitor

    Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to ga

    MediumCVSS 6.9No exploitEPSS 0%

    monkey-project · monkeyOct 5, 2012

  • CVE-2012-5303
    27Monitor

    Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathn

    MediumCVSS 6.9No exploitEPSS 0%

    monkey-project · monkeyOct 5, 2012

  • CVE-2013-2182
    25Monitor

    The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted

    MediumCVSS 5.8Proof of conceptEPSS 6%

    monkey-project · monkeyJun 13, 2014

  • CVE-2013-3724
    24Monitor

    The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash an

    MediumCVSS 5.0Proof of conceptEPSS 14%

    monkey-project · monkeyAug 1, 2013

  • CVE-2002-2154
    22Monitor

    Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..

    MediumCVSS 5.0Proof of conceptEPSS 8%

    monkey-project · monkeyDec 31, 2002

  • CVE-2002-1663
    21Monitor

    The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a

    MediumCVSS 5.0Proof of conceptEPSS 4%

    monkey-project · monkeyDec 31, 2002

  • CVE-2004-0276
    21Monitor

    The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash)

    MediumCVSS 5.0Proof of conceptEPSS 4%

    monkey-project · monkeyNov 23, 2004

  • CVE-2013-2163
    21Monitor

    Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fi

    MediumCVSS 5.0No exploitEPSS 3%

    monkey-project · monkeyJun 13, 2014

  • CVE-2003-1209
    21Monitor

    The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request

    MediumCVSS 5.0No exploitEPSS 2%

    monkey-project · monkeyDec 31, 2003

  • CVE-2005-1123
    20Monitor

    Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte

    MediumCVSS 5.0No exploitEPSS 2%

    monkey-project · monkeyMay 2, 2005