Mono Project maintains a cross-platform implementation of the .NET framework widely used in server and desktop applications, though its vulnerability footprint remains modestly represented relative to its deployment scope. The recurring exposure concentrates in the core Mono runtime and graphics library (libgdiplus) and clusters around input-handling weaknesses including improper validation and cross-site scripting, typical of runtime interpreters and graphics-processing components that parse untrusted data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mono Project over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4254HIGH Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con | Dec 6, 2010 | 7.5 | 42 | NO | YES |
CVE-2015-2320CRITICAL The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. | Jan 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2008-3906MEDIUM CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen | Sep 4, 2008 | 4.3 | 29 | NO | YES |
CVE-2023-26314HIGH The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono | Feb 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-12471CRITICAL MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5U | Apr 29, 2020 | 9.8 | 25 | NO | NO |
CVE-2012-3543HIGH mono 2.10.x ASP.NET Web Form Hash collision DoS | Nov 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2006-6104MEDIUM The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by append | Dec 21, 2006 | 5.0 | 24 | NO | YES |
CVE-2019-0757MEDIUM A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet | Apr 9, 2019 | 6.5 | 23 | NO | NO |
CVE-2015-2319HIGH The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i | Jan 8, 2018 | 7.5 | 23 | NO | NO |
CVE-2015-2318HIGH The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat | Jan 8, 2018 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mono Project.
Media articles that mention a CVE ID that affects a product developed by Mono Project — matched by CVE ID, not by vendor name.