Mono
Vendor:
First CVE: Mar 14, 2005 · Active for 21 years
21
Total CVEs
More Total CVEs than 87% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mono over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2005
21 years ago
Most Recent CVE
Feb 22, 2023
1,252 days ago
CVE Severity & Scoring
Mono21 CVEs
67%
29%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (23.8%)
Unknown16 (76.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (19.0%)
High1 (4.8%)
Unknown16 (76.2%)
User Interaction
None4 (19.0%)
Unknown16 (76.2%)
Required1 (4.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (23.8%)
Unknown16 (76.2%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4254HIGH Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con | Dec 6, 2010 | 7.5 | 42 | NO | YES |
CVE-2015-2320CRITICAL The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. | Jan 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2008-3906MEDIUM CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen | Sep 4, 2008 | 4.3 | 29 | NO | YES |
CVE-2023-26314HIGH The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono | Feb 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2012-3543HIGH mono 2.10.x ASP.NET Web Form Hash collision DoS | Nov 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2015-2319HIGH The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i | Jan 8, 2018 | 7.5 | 23 | NO | NO |
CVE-2015-2318HIGH The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat | Jan 8, 2018 | 8.1 | 23 | NO | NO |
CVE-2010-4159MEDIUM Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working dire | Nov 17, 2010 | 6.9 | 23 | NO | NO |
CVE-2009-0217MEDIUM The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle | Jul 14, 2009 | 5.0 | 22 | NO | NO |
CVE-2011-0989MEDIUM The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which al | Apr 13, 2011 | 5.8 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Mono
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.8.0.105\+dfsg-3 | 1 | 8.8 | 1.0% | 0 | 0 |
| 5.18.0.240\+dfsg-3 | 1 | 8.8 | 1.0% | 0 | 0 |
| 2.8.1 | 1 | 5.0 | 1.5% | 0 | 0 |
| 2.8 | 1 | 5.0 | 1.5% | 0 | 0 |
| 2.6.4 | 1 | 6.9 | 0.4% | 0 | 0 |
| 2.6.3 | 1 | 6.9 | 0.4% | 0 | 0 |
| 2.6 | 1 | 6.9 | 0.4% | 0 | 0 |
| 2.4.3 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.4.2.3 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.4.2.2 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.4.2.1 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.4.2 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.4 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.2 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.0.1 | 2 | 5.6 | 1.1% | 0 | 0 |
| 2.0 | 4 | 5.6 | 2.3% | 0 | 0 |
| 1.9.1 | 2 | 5.6 | 1.1% | 0 | 0 |
| 1.9 | 5 | 5.0 | 3.5% | 0 | 1 |
| 1.2.6 | 5 | 5.0 | 3.5% | 0 | 1 |
| 1.2.5.2 | 2 | 5.6 | 1.1% | 0 | 0 |