Записи monkey-project
29 опубликованных записей вендора monkey-project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,4 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation6
- CWE-125 Out-of-bounds Read5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-416 Use After Free2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2013-2159Эксплойта нет | Monkey HTTP Daemon: broken user name authenticationmonkey-project · monkey · CWE-287 | Критическая9,8 | — | 2,8 % | 10 дек. 2019 г. |
33Наблюдать | CVE-2013-3843Готовый эксплойт | Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remonkey-project · monkey · CWE-119 | Средняя6,8 | — | 20,2 % | 13 июн. 2014 г. |
33Наблюдать | CVE-2025-63655Эксплойта нет | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Demonkey-project · monkey · CWE-476 | Высокая7,5 | — | 8,6 % | 29 янв. 2026 г. |
32Наблюдать | CVE-2003-0218Эксплойта нет | Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary codmonkey-project · monkey · CWE-119 | Высокая7,5 | — | 5,2 % | 12 мая 2003 г. |
31Наблюдать | CVE-2013-1771Эксплойта нет | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.monkey-project · monkey · CWE-532 | Высокая7,5 | — | 3,0 % | 7 нояб. 2019 г. |
31Наблюдать | CVE-2005-1122Эксплойта нет | Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possimonkey-project · monkey · CWE-134 | Высокая7,5 | — | 2,7 % | 14 апр. 2005 г. |
30Наблюдать | CVE-2025-63658Эксплойта нет | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Smonkey-project · monkey · CWE-121 | Высокая7,5 | — | 1,3 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63656Эксплойта нет | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial ofmonkey-project · monkey · CWE-125 | Высокая7,5 | — | 1,2 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63650Эксплойта нет | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-125 | Высокая7,5 | — | 1,2 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63652Эксплойта нет | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Semonkey-project · monkey · CWE-416 | Высокая7,5 | — | 1,2 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63653Эксплойта нет | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial monkey-project · monkey · CWE-125 | Высокая7,5 | — | 1,2 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63657Эксплойта нет | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denialmonkey-project · monkey · CWE-125 | Высокая7,5 | — | 1,2 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63649Эксплойта нет | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attmonkey-project · monkey · CWE-125 | Высокая7,5 | — | 1,1 % | 29 янв. 2026 г. |
30Наблюдать | CVE-2025-63651Эксплойта нет | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of monkey-project · monkey · CWE-416 | Высокая7,5 | — | 1,1 % | 29 янв. 2026 г. |
28Наблюдать | CVE-2013-2183Эксплойта нет | Monkey HTTP Daemon has local security bypassmonkey-project · monkey · CWE-668 | Высокая7,1 | — | 0,4 % | 10 дек. 2019 г. |
27Наблюдать | CVE-2012-4443Эксплойта нет | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gamonkey-project · monkey · CWE-264 | Средняя6,9 | — | 0,4 % | 5 окт. 2012 г. |
27Наблюдать | CVE-2012-5303Эксплойта нет | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathnmonkey-project · monkey · CWE-59 | Средняя6,9 | — | 0,3 % | 5 окт. 2012 г. |
25Наблюдать | CVE-2013-2182Proof of concept | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a craftedmonkey-project · monkey · CWE-264 | Средняя5,8 | — | 5,6 % | 13 июн. 2014 г. |
24Наблюдать | CVE-2013-3724Proof of concept | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash anmonkey-project · monkey · CWE-20 | Средняя5,0 | — | 13,7 % | 1 авг. 2013 г. |
22Наблюдать | CVE-2002-2154Proof of concept | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..monkey-project · monkey · CWE-22 | Средняя5,0 | — | 7,6 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2002-1663Proof of concept | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a monkey-project · monkey · CWE-20 | Средняя5,0 | — | 4,0 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2004-0276Proof of concept | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) monkey-project · monkey · CWE-20 | Средняя5,0 | — | 3,7 % | 23 нояб. 2004 г. |
21Наблюдать | CVE-2013-2163Эксплойта нет | Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fimonkey-project · monkey · CWE-20 | Средняя5,0 | — | 2,5 % | 13 июн. 2014 г. |
21Наблюдать | CVE-2003-1209Эксплойта нет | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request monkey-project · monkey · CWE-20 | Средняя5,0 | — | 2,4 % | 31 дек. 2003 г. |
20Наблюдать | CVE-2005-1123Эксплойта нет | Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte monkey-project · monkey · CWE-119 | Средняя5,0 | — | 1,6 % | 2 мая 2005 г. |
- CVE-2013-215940В плане
Monkey HTTP Daemon: broken user name authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %monkey-project · monkey10 дек. 2019 г.
- CVE-2013-384333Наблюдать
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows re
СредняяCVSS 6,8Готовый эксплойтEPSS 20 %monkey-project · monkey13 июн. 2014 г.
- CVE-2025-6365533Наблюдать
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a De
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %monkey-project · monkey29 янв. 2026 г.
- CVE-2003-021832Наблюдать
Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary cod
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %monkey-project · monkey12 мая 2003 г.
- CVE-2013-177131Наблюдать
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %monkey-project · monkey7 нояб. 2019 г.
- CVE-2005-112231Наблюдать
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %monkey-project · monkey14 апр. 2005 г.
- CVE-2025-6365830Наблюдать
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of S
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365630Наблюдать
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365030Наблюдать
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365230Наблюдать
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Se
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365330Наблюдать
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365730Наблюдать
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6364930Наблюдать
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows att
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2025-6365130Наблюдать
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monkey-project · monkey29 янв. 2026 г.
- CVE-2013-218328Наблюдать
Monkey HTTP Daemon has local security bypass
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %monkey-project · monkey10 дек. 2019 г.
- CVE-2012-444327Наблюдать
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to ga
СредняяCVSS 6,9Эксплойта нетEPSS 0 %monkey-project · monkey5 окт. 2012 г.
- CVE-2012-530327Наблюдать
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathn
СредняяCVSS 6,9Эксплойта нетEPSS 0 %monkey-project · monkey5 окт. 2012 г.
- CVE-2013-218225Наблюдать
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted
СредняяCVSS 5,8Proof of conceptEPSS 6 %monkey-project · monkey13 июн. 2014 г.
- CVE-2013-372424Наблюдать
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash an
СредняяCVSS 5,0Proof of conceptEPSS 14 %monkey-project · monkey1 авг. 2013 г.
- CVE-2002-215422Наблюдать
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via ..
СредняяCVSS 5,0Proof of conceptEPSS 8 %monkey-project · monkey31 дек. 2002 г.
- CVE-2002-166321Наблюдать
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a
СредняяCVSS 5,0Proof of conceptEPSS 4 %monkey-project · monkey31 дек. 2002 г.
- CVE-2004-027621Наблюдать
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash)
СредняяCVSS 5,0Proof of conceptEPSS 4 %monkey-project · monkey23 нояб. 2004 г.
- CVE-2013-216321Наблюдать
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the fi
СредняяCVSS 5,0Эксплойта нетEPSS 3 %monkey-project · monkey13 июн. 2014 г.
- CVE-2003-120921Наблюдать
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request
СредняяCVSS 5,0Эксплойта нетEPSS 2 %monkey-project · monkey31 дек. 2003 г.
- CVE-2005-112320Наблюдать
Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte
СредняяCVSS 5,0Эксплойта нетEPSS 2 %monkey-project · monkey2 мая 2005 г.