Mono is a cross-platform runtime framework and associated tools that enable execution of .NET applications on non-Windows environments, with a footprint spanning the core runtime, web server components like XSP, graphics libraries such as libgdiplus, and related middleware. The vendor's vulnerability surface clusters around input-handling and web-layer weaknesses—including cross-site scripting, improper input validation, and information-disclosure flaws—characteristic of interpreters and web frameworks that parse untrusted application code and HTTP traffic. While the vendor's disclosures do not skew toward critical severity, public exploit code has an elevated tendency to emerge for identified flaws, reflecting the accessible nature of web and runtime attack vectors. Defenders deploying Mono should prioritize patches for web-facing components and validate input handling in hosted applications; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mono over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4254HIGH Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con | Dec 6, 2010 | 7.5 | 42 | NO | YES |
CVE-2015-2320CRITICAL The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. | Jan 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2008-3906MEDIUM CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen | Sep 4, 2008 | 4.3 | 29 | NO | YES |
CVE-2023-26314HIGH The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono | Feb 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-12471CRITICAL MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5U | Apr 29, 2020 | 9.8 | 25 | NO | NO |
CVE-2012-3543HIGH mono 2.10.x ASP.NET Web Form Hash collision DoS | Nov 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2006-6104MEDIUM The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by append | Dec 21, 2006 | 5.0 | 24 | NO | YES |
CVE-2019-0757MEDIUM A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet | Apr 9, 2019 | 6.5 | 23 | NO | NO |
CVE-2015-2319HIGH The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i | Jan 8, 2018 | 7.5 | 23 | NO | NO |
CVE-2015-2318HIGH The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat | Jan 8, 2018 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mono.
Media articles that mention a CVE ID that affects a product developed by Mono — matched by CVE ID, not by vendor name.