Monotone is a distributed version-control system with a narrow deployment footprint, and its recorded vulnerabilities reflect the limited scope of the product. The observed weakness classes have been classified broadly as "Other" in NVD records, indicating either low specificity or non-standard flaw categories for this specialized software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monotone over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4098MEDIUM monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command. | Oct 27, 2010 | 5.0 | 18 | NO | NO |
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, pla | Mar 12, 2006 | 3.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monotone.
Media articles that mention a CVE ID that affects a product developed by Monotone — matched by CVE ID, not by vendor name.