Mono

Vendor:

First CVE: Mar 14, 2005 · Active for 21 years

21
Total CVEs
More Total CVEs than 87% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mono over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2005
21 years ago
Most Recent CVE
Feb 22, 2023
1,252 days ago

CVE Severity & Scoring

Mono21 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (23.8%)
Unknown16 (76.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (19.0%)
High1 (4.8%)
Unknown16 (76.2%)
User Interaction
None4 (19.0%)
Unknown16 (76.2%)
Required1 (4.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (23.8%)
Unknown16 (76.2%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con
Dec 6, 20107.542NOYES
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Jan 8, 20189.831NONO
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen
Sep 4, 20084.329NOYES
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono
Feb 22, 20238.827NONO
mono 2.10.x ASP.NET Web Form Hash collision DoS
Nov 21, 20197.524NONO
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i
Jan 8, 20187.523NONO
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat
Jan 8, 20188.123NONO
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working dire
Nov 17, 20106.923NONO
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle
Jul 14, 20095.022NONO
The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which al
Apr 13, 20115.821NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Mono

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.8.0.105\+dfsg-318.81.0%00
5.18.0.240\+dfsg-318.81.0%00
2.8.115.01.5%00
2.815.01.5%00
2.6.416.90.4%00
2.6.316.90.4%00
2.616.90.4%00
2.4.325.61.1%00
2.4.2.325.61.1%00
2.4.2.225.61.1%00
2.4.2.125.61.1%00
2.4.225.61.1%00
2.425.61.1%00
2.225.61.1%00
2.0.125.61.1%00
2.045.62.3%00
1.9.125.61.1%00
1.955.03.5%01
1.2.655.03.5%01
1.2.5.225.61.1%00