Releases0
Stars38
๐Ÿš Mono repo for several npm packages

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 6.8.0.105+dfsg-3, = 5.18.0.240+dfsg-38.8 HIGHโ€”

The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

>= 2.10, <= 2.10.127.5 HIGH5 MEDIUM

mono 2.10.x ASP.NET Web Form Hash collision DoS

< 3.12.1โ€”7.5 HIGH

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

< 3.12.1โ€”5 MEDIUM

The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

< 3.12.1โ€”6.8 MEDIUM

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

<= 2.10.8โ€”4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.

all versionsโ€”5.8 MEDIUM

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.

all versionsโ€”5.8 MEDIUM

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.

all versionsโ€”6.8 MEDIUM

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.

all versionsโ€”5.8 MEDIUM

Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.

= 2.8, = 2.8.1โ€”5 MEDIUM

Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug."

all versionsโ€”7.5 HIGH

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

= 2.4.2.2, = 1.1.17.2, = 1.1.11, = 1.9, = 1.1.13.8, = 2.2, = 1.1.13.4, <= 2.6.7, = 1.1.13.5, = 1.1.10, = 1.1.3, = 1.2.4, = 1.0.1, = 1.1.13, = 1.1.8.3, = 1.1.6, = 1.2.5.2, = 1.0, = 1.0.2, = 2.0.1, = 1.1.8, = 1.1.5, = 2.4.2.3, = 1.2.1, = 1.2.2, = 2.6.3, = 2.6, = 1.1.8.1, = 1.1.17, = 1.1.10.1, = 1.0.6, = 1.1.13.6, = 1.0.5, = 1.2.3.1, = 2.4, = 1.1.13.2, = 1.1.12, = 1.1.15, = 1.1.16, = 1.1.17.1, = 1.1.2, = 1.1.9, = 1.1.18, = 1.1.7, = 1.1.9.1, = 1.1.1, = 1.2.5.1, = 1.9.1, = 2.4.3, = 1.1.13.8.1, = 1.1.14, = 1.2.2.1, = 2.6.4, = 1.2.5, = 2.4.2.1, = 2.4.2, = 2.0, = 1.1.16.1, = 1.2, = 1.1.4, = 1.1.13.7, = 1.0.4, = 1.2.6, = 1.2.3, = 1.1.12.1, = 1.1.9.2โ€”6.9 MEDIUM

Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.

= 2.4.2.2, = 1.1.17.2, = 1.1.11, = 1.9, = 1.1.13.8, = 2.2, = 1.1.13.4, = 1.1.13.5, = 1.2.2, = 1.2.5.2, = 1.2.1, = 1.2.5.1, = 1.1.8.3, = 1.2.4, = 1.1.8, = 1.0.2, = 1.1.17.1, = 1.0, = 2.4.2.3, = 1.1.3, = 1.1.13, = 2.0.1, = 1.1.15, = 1.1.10, = 1.1.6, = 1.1.5, = 1.0.1, = 1.1.17, = 1.1.13.7, = 2.4.2.1, = 1.2.6, = 1.2, = 1.1.13.2, = 1.1.12.1, = 1.1.9, = 1.1.8.1, = 1.1.1, = 1.0.6, = 1.1.13.6, = 2.4.2, = 2.4, = 1.2.5, = 1.1.16.1, = 1.1.16, = 1.1.12, = 1.1.7, = 1.0.4, = 2.4.3, = 1.9.1, = 1.2.2.1, = 1.1.13.8.1, = 1.1.9.2, = 1.1.9.1, = 1.1.2, = 1.1.4, = 1.1.18, = 1.0.5, = 1.2.3.1, = 1.2.3, = 1.1.14, = 1.1.10.1, = 2.0, < 2.6.4โ€”4.3 MEDIUM

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

= 1.2.4, = 1.2.1, = 1.9, = 1.2.6, = 2.0, = 1.2.3, = 1.2.5, = 1.2.2โ€”5 MEDIUM

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

= 1.2.4, = 1.2.1, = 1.9, = 1.2.6, = 1.1.13.4, = 1.1.13, = 1.0, = 1.1.8.3, = 1.2.3, = 1.0.5, = 1.2.5.1, <= 2.0, = 1.1.17.1, = 1.1.4, = 1.1.17, = 1.1.18, = 1.2.5, = 1.1.13.6, = 1.1.13.7, = 1.2.2โ€”4.3 MEDIUM

CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

= 1.2.4, = 1.2.1, = 1.9, = 1.2.6, = 1.1.13.4, = 1.1.13, = 1.0, = 1.1.8.3, = 1.2.3, = 1.1.18, = 1.1.4, = 1.2.5, = 1.1.13.6, = 1.1.13.7, = 1.2.2, = 1.0.5, = 1.2.5.1, <= 2.0, = 1.1.17, = 1.1.17.1โ€”4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).

<= 1.2.5.1, = 1.0, = 1.0.5, = 1.1.4, = 1.1.8.3, = 1.1.13, = 1.1.13.4, = 1.1.13.6, = 1.1.13.7, = 1.1.17, = 1.1.17.1, = 1.1.18โ€”7.5 HIGH

Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.

<= 1.2.5.1โ€”5 MEDIUM

StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.

= 1.0, = 2.0โ€”6.2 MEDIUM

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

= 1.0.5โ€”4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".