Monit

Vendor:

First CVE: Nov 24, 2003 · Active for 22 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Monit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2003
22 years ago
Most Recent CVE
Jul 18, 2023
1,105 days ago

CVE Severity & Scoring

Monit7 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (42.9%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None1 (14.3%)
Unknown4 (57.1%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.
Dec 31, 200310.053NOYES
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
Dec 31, 200410.043NOYES
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password chang
Apr 22, 20199.829NONO
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation
Apr 22, 20198.128NONO
An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.
Jul 18, 20238.824NONO
Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.
Nov 24, 20035.020NONO
The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.
Dec 31, 20045.015NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Monit

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.3_beta_227.59.1%01
4.227.59.1%01
4.1.127.59.1%01
4.147.510.8%02
4.047.510.8%02
3.247.510.8%02
3.147.510.8%02
3.047.510.8%02
2.4.327.512.4%01
2.4.227.512.4%01
2.4.127.512.4%01
2.427.512.4%01
2.327.512.4%01
2.2.127.512.4%01
2.227.512.4%01
2.1.127.512.4%01
2.127.512.4%01
2.027.512.4%01
1.4.127.512.4%01
1.447.510.8%02