cbcvebase.

Debian Mono vulnerabilities

18 known vulnerabilities affecting debian/mono.

Total CVEs
18
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM10LOW3

Vulnerabilities

Page 1 of 1
CVE-2009-0689P3MEDIUMCVSS 6.8PoCfixed in mono 4.2.1.102+dfsg2-4 (bookworm)2009
CVE-2009-0689 [MEDIUM] CVE-2009-0689: mono - Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the... Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, al
debian
CVE-2015-2320P3CRITICALCVSS 9.8fixed in mono 3.2.8+dfsg-10 (bookworm)2015
CVE-2015-2320 [CRITICAL] CVE-2015-2320: mono - The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified ... The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. Scope: local bookworm: resolved (fixed in 3.2.8+dfsg-10) bullseye: resolved (fixed in 3.2.8+dfsg-10) forky: resolved (fixed in 3.2.8+dfsg-10) sid: resolved (fixed in 3.2.8+dfsg-10) trixie: resolved (fixed in 3.2.8+dfsg-10)
debian
CVE-2006-6104P4LOWCVSS 5.0PoCfixed in mono 1.2.2.1-1 (bookworm)2006
CVE-2006-6104 [MEDIUM] CVE-2006-6104: mono - The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does ... The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20. Scope: local bookworm: resolved (fixed in 1.2.2.1-1) bullseye: resolved (fixed in 1.2.2.1-1) forky: resol
debian
CVE-2008-3906P4LOWCVSS 4.3PoCfixed in mono 1.9.1+dfsg-4 (bookworm)2008
CVE-2008-3906 [MEDIUM] CVE-2008-3906: mono - CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote at... CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. Scope: local bookworm: resolved (fixed in 1.9.1+dfsg-4) bullseye: resolved (fixed in 1.9.1+dfsg-4) forky: resolved (fixed in 1.9.1+dfsg-4) sid: resolved (fixed in 1.9
debian
CVE-2023-26314P3HIGHCVSS 8.8fixed in mono 6.8.0.105+dfsg-3.3 (bookworm)2023
CVE-2023-26314 [HIGH] CVE-2023-26314: mono - The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code exec... The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter. Scope: local bookworm: resolved (fixed in 6.8.0.105+dfsg-3.3) bullseye: resolved (fixed in 6.8.0.105+dfsg-3.3~deb11u1) forky: resolved (fixed in 6.8.0.105+dfsg-3.3) sid: reso
debian
CVE-2015-2319P3MEDIUMCVSS 4.3fixed in mono 3.2.8+dfsg-10 (bookworm)2015
CVE-2015-2319 [MEDIUM] CVE-2015-2319: mono - The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to cond... The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204. Scope: local bookworm: resolved (fixed in 3.2.8+dfsg-10) bullseye: resolved (fixed in 3.2.8+dfsg-10) forky: resolved (fixed in 3.2.8+dfsg-1
debian
CVE-2015-2318P3HIGHCVSS 8.1fixed in mono 3.2.8+dfsg-10 (bookworm)2015
CVE-2015-2318 [HIGH] CVE-2015-2318: mono - The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduc... The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue. Scope: local bookworm: resolved (fixed in 3.2.8+dfsg-10) bullseye: resolved (fixed in 3.2.8+dfsg-10) forky: resolved (fixed in 3.2.8+dfsg-10) sid: re
debian
CVE-2018-1002208P3MEDIUMCVSS 5.5fixed in mono 5.18.0.240+dfsg-1 (bookworm)2018
CVE-2018-1002208 [MEDIUM] CVE-2018-1002208: mono - SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attack... SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. Scope: local bookworm: resolved (fixed in 5.18.0.240+dfsg-1) bullseye: resolved (fixed in 5.18.0.240+dfsg-1) forky: re
debian
CVE-2007-5197P3HIGHCVSS 7.5fixed in mono 1.2.5.1-2 (bookworm)2007
CVE-2007-5197 [HIGH] CVE-2007-5197: mono - Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier al... Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods. Scope: local bookworm: resolved (fixed in 1.2.5.1-2) bullseye: resolved (fixed in 1.2.5.1-2) forky: resolved (fixed in 1.2.5.1-2) sid: resolved (fixed in 1.2.5
debian
CVE-2009-0217P3MEDIUMCVSS 5.0fixed in mono 2.4.2.3+dfsg-1 (bookworm)2009
CVE-2009-0217 [MEDIUM] CVE-2009-0217: mono - The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendati... The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML
debian
CVE-2005-0509P4MEDIUMCVSS 4.3fixed in mono 1.1.6-4 (bookworm)2005
CVE-2005-0509 [MEDIUM] CVE-2005-0509: mono - Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementa... Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<". Scope: local bookworm: resolved (fixed in 1.1.6-4) bullseye: resolved (fixed
debian
CVE-2010-4225P4MEDIUMCVSS 5.0fixed in mono 2.6.7-5 (bookworm)2010
CVE-2010-4225 [MEDIUM] CVE-2010-4225: mono - Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.... Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug." Scope: local bookworm: resolved (fixed in 2.6.7-5) bullseye: resolved (fixed in 2.6.7-5) forky: resolved (fixed in 2.6.7-5) sid: resolved (fixed in 2.6.7
debian
CVE-2012-3382P4MEDIUMCVSS 4.3fixed in mono 2.10.8.1-5 (bookworm)2012
CVE-2012-3382 [MEDIUM] CVE-2012-3382: mono - Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/c... Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message. Scope: local bookworm: resolved (fixed in
debian
CVE-2010-4159P4MEDIUMCVSS 6.9fixed in mono 2.6.7-4 (bookworm)2010
CVE-2010-4159 [MEDIUM] CVE-2010-4159: mono - Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier... Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory. Scope: local bookworm: resolved (fixed in 2.6.7-4) bullseye: resolved (fixed in 2.6.7-4) forky: resolved (fixed in 2.6.7-4) sid: resolved (fixed in 2.6.7-4) trixie: resolved (fixed in
debian
CVE-2006-5072P4MEDIUMCVSS 6.2fixed in mono 1.1.17.1-5 (bookworm)2006
CVE-2006-5072 [MEDIUM] CVE-2006-5072: mono - The System.CodeDom.Compiler classes in Novell Mono create temporary files with i... The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack. Scope: local bookworm: resolved (fixed in 1.1.17.1-5) bullseye: resolved (fixed in 1.1.17.1-5) forky: resolved (fixed in 1.1.17.1-5) sid: resolved (fixed in 1.1.17.1-5)
debian
CVE-2010-1459P4MEDIUMCVSS 4.3fixed in mono 2.4.4~svn151842-3 (bookworm)2010
CVE-2010-1459 [MEDIUM] CVE-2010-1459: mono - The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE f... The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project. Scope: local bookworm: resolved (fixed in 2.4.4~svn151842-3) bullseye: resolved (fi
debian
CVE-2008-3422P4LOWCVSS 4.3fixed in mono 1.9.1+dfsg-4 (bookworm)2008
CVE-2008-3422 [MEDIUM] CVE-2008-3422: mono - Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class librari... Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes
debian
CVE-2012-3543HIGHCVSS 7.5fixed in mono 2.10.8.1-7 (bookworm)2012
CVE-2012-3543 [HIGH] CVE-2012-3543: mono - mono 2.10.x ASP.NET Web Form Hash collision DoS mono 2.10.x ASP.NET Web Form Hash collision DoS Scope: local bookworm: resolved (fixed in 2.10.8.1-7) bullseye: resolved (fixed in 2.10.8.1-7) forky: resolved (fixed in 2.10.8.1-7) sid: resolved (fixed in 2.10.8.1-7) trixie: resolved (fixed in 2.10.8.1-7)
debian
Debian Mono vulnerabilities | cvebase