Skip to main content

Vendor archive

mono CVEs

Beta · best-effort

21 CVEs tagged to vendor mono1 Critical, 4 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2020-12471

Published Apr 29, 2020

MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12470

Published Apr 29, 2020

MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12473

Published Apr 29, 2020

MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12472

Published Apr 29, 2020

MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3382

Published Jul 12, 2012

Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0992

Published Apr 13, 2011

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain s…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0991

Published Apr 13, 2011

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecifi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0990

Published Apr 13, 2011

Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attac…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0989

Published Apr 13, 2011

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4225

Published Jan 11, 2011

Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4254

Published Dec 6, 2010

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4159

Published Nov 17, 2010

Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working dir…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1459

Published May 27, 2010

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3906

Published Sep 4, 2008

CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF seque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3422

Published Jul 31, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5473

Published Oct 18, 2007

StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a tra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6104

Published Dec 21, 2006

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5072

Published Oct 10, 2006

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary cod…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0509

Published Mar 14, 2005

Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1