mono kayıtları
mono üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %52,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-12471İstismar yok | MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because ofmono · monox · CWE-502 | Kritik9,8 | — | %2,8 | 29 Nis 2020 |
34İzleyin | CVE-2010-4254Kavram kanıtı | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allowmono · mono · CWE-20 | Yüksek7,5 | — | %13,6 | 6 Ara 2010 |
31İzleyin | CVE-2007-5197İstismar yok | Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code vmono · mono · CWE-119 | Yüksek7,5 | — | %3,6 | 2 Kas 2007 |
29İzleyin | CVE-2020-12470İstismar yok | MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.mono · monox · CWE-552 | Yüksek7,2 | — | %1,7 | 29 Nis 2020 |
28İzleyin | CVE-2011-0991İstismar yok | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a deniamono · mono · CWE-399 | Orta6,8 | — | %2,9 | 13 Nis 2011 |
28İzleyin | CVE-2020-12473İstismar yok | MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to amono · monox | Yüksek7,2 | — | %1,4 | 29 Nis 2020 |
27İzleyin | CVE-2010-4159İstismar yok | Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shmono · mono | Orta6,9 | — | %0,4 | 17 Kas 2010 |
24İzleyin | CVE-2011-0992İstismar yok | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a deniamono · mono · CWE-399 | Orta5,8 | — | %2,7 | 13 Nis 2011 |
24İzleyin | CVE-2011-0989İstismar yok | The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does nomono · mono · CWE-264 | Orta5,8 | — | %2,7 | 13 Nis 2011 |
24İzleyin | CVE-2011-0990İstismar yok | Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x befmono · mono · CWE-362 | Orta5,8 | — | %2,2 | 13 Nis 2011 |
24İzleyin | CVE-2006-5072İstismar yok | The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite amono · mono | Orta6,2 | — | %0,5 | 10 Eki 2006 |
22İzleyin | CVE-2005-0509İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbimono · mono | Orta4,3 | — | %15,9 | 14 Mar 2005 |
22İzleyin | CVE-2006-6104Kavram kanıtı | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attmono · xsp | Orta5,0 | — | %5,2 | 21 Ara 2006 |
21İzleyin | CVE-2006-2658İstismar yok | Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE mono · xsp | Orta5,0 | — | %3,9 | 12 Eyl 2006 |
21İzleyin | CVE-2020-12472İstismar yok | MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.mono · monox · CWE-79 | Orta5,4 | — | %0,5 | 29 Nis 2020 |
20İzleyin | CVE-2010-4225İstismar yok | Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .amono · mono · CWE-200 | Orta5,0 | — | %1,5 | 10 Oca 2011 |
20İzleyin | CVE-2007-5473İstismar yok | StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitimono · mono · CWE-200 | Orta5,0 | — | %1,3 | 18 Eki 2007 |
19İzleyin | CVE-2008-3906Kavram kanıtı | CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP remono · mono · CWE-20 | Orta4,3 | — | %7,1 | 4 Eyl 2008 |
18İzleyin | CVE-2010-1459İstismar yok | The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attamono · mono · CWE-79 | Orta4,3 | — | %1,9 | 27 May 2010 |
18İzleyin | CVE-2012-3382İstismar yok | Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2mono · mono · CWE-79 | Orta4,3 | — | %1,9 | 12 Tem 2012 |
17İzleyin | CVE-2008-3422İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject mono · mono · CWE-79 | Orta4,3 | — | %1,6 | 31 Tem 2008 |
- CVE-2020-1247140Planlayın
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of
KritikCVSS 9,8İstismar yokEPSS %3mono · monox29 Nis 2020
- CVE-2010-425434İzleyin
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allow
YüksekCVSS 7,5Kavram kanıtıEPSS %14mono · mono6 Ara 2010
- CVE-2007-519731İzleyin
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code v
YüksekCVSS 7,5İstismar yokEPSS %4mono · mono2 Kas 2007
- CVE-2020-1247029İzleyin
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
YüksekCVSS 7,2İstismar yokEPSS %2mono · monox29 Nis 2020
- CVE-2011-099128İzleyin
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denia
OrtaCVSS 6,8İstismar yokEPSS %3mono · mono13 Nis 2011
- CVE-2020-1247328İzleyin
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a
YüksekCVSS 7,2İstismar yokEPSS %1mono · monox29 Nis 2020
- CVE-2010-415927İzleyin
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse sh
OrtaCVSS 6,9İstismar yokEPSS %0mono · mono17 Kas 2010
- CVE-2011-099224İzleyin
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denia
OrtaCVSS 5,8İstismar yokEPSS %3mono · mono13 Nis 2011
- CVE-2011-098924İzleyin
The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does no
OrtaCVSS 5,8İstismar yokEPSS %3mono · mono13 Nis 2011
- CVE-2011-099024İzleyin
Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x bef
OrtaCVSS 5,8İstismar yokEPSS %2mono · mono13 Nis 2011
- CVE-2006-507224İzleyin
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite a
OrtaCVSS 6,2İstismar yokEPSS %0mono · mono10 Eki 2006
- CVE-2005-050922İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbi
OrtaCVSS 4,3İstismar yokEPSS %16mono · mono14 Mar 2005
- CVE-2006-610422İzleyin
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote att
OrtaCVSS 5,0Kavram kanıtıEPSS %5mono · xsp21 Ara 2006
- CVE-2006-265821İzleyin
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE
OrtaCVSS 5,0İstismar yokEPSS %4mono · xsp12 Eyl 2006
- CVE-2020-1247221İzleyin
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
OrtaCVSS 5,4İstismar yokEPSS %1mono · monox29 Nis 2020
- CVE-2010-422520İzleyin
Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .a
OrtaCVSS 5,0İstismar yokEPSS %1mono · mono10 Oca 2011
- CVE-2007-547320İzleyin
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensiti
OrtaCVSS 5,0İstismar yokEPSS %1mono · mono18 Eki 2007
- CVE-2008-390619İzleyin
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP re
OrtaCVSS 4,3Kavram kanıtıEPSS %7mono · mono4 Eyl 2008
- CVE-2010-145918İzleyin
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote atta
OrtaCVSS 4,3İstismar yokEPSS %2mono · mono27 May 2010
- CVE-2012-338218İzleyin
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2
OrtaCVSS 4,3İstismar yokEPSS %2mono · mono12 Tem 2012
- CVE-2008-342217İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject
OrtaCVSS 4,3İstismar yokEPSS %2mono · mono31 Tem 2008