Mono-Project Mono vulnerabilities

4 known vulnerabilities affecting mono-project/mono.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2023-26314HIGHCVSS 8.8v5.18.0.240\+dfsg-3v6.8.0.105\+dfsg-32023-02-22
CVE-2023-26314 [HIGH] CVE-2023-26314: The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the ap The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.
nvd
CVE-2015-2320CRITICALCVSS 9.8fixed in 3.12.12018-01-08
CVE-2015-2320 [CRITICAL] CWE-295 CVE-2015-2320: The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors r The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
nvd
CVE-2015-2319HIGHCVSS 7.5fixed in 3.12.12018-01-08
CVE-2015-2319 [HIGH] CVE-2015-2319: The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
nvd
CVE-2015-2318HIGHCVSS 8.1fixed in 3.12.12018-01-08
CVE-2015-2318 [HIGH] CWE-295 CVE-2015-2318: The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping a The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
nvd