Search CVE reports
21 – 30 of 31 results
CVE-2010-4098
Low prioritymonotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.
1 affected packages
monotone
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
monotone | — | — | — | — | — |
CVE-2010-3369
Low priorityThe (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared...
1 affected packages
mono-debugger
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono-debugger | — | — | — | — | — |
CVE-2010-1459
Low prioritySome fixes available 1 of 5
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE...
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2009-0217
Medium prioritySome fixes available 11 of 23
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and...
7 affected packages
libreoffice, libxml-security-java, mono, openjdk-6, openoffice.org...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libreoffice | — | — | — | — | — |
libxml-security-java | — | — | — | — | — |
mono | — | — | — | — | — |
openjdk-6 | — | — | — | — | — |
openoffice.org | — | — | — | — | — |
xml-security-c | — | — | — | — | — |
xmlsec1 | — | — | — | — | — |
CVE-2008-3906
Low prioritySome fixes available 1 of 4
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2008-3422
Low prioritySome fixes available 1 of 4
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs...
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2007-5197
Medium priorityBuffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2006-6104
Unknown priorityThe System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2)...
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2006-5072
Unknown priorityThe System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.
1 affected packages
mono
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mono | — | — | — | — | — |
CVE-2006-1046
Unknown prioritySome fixes available 6 of 8
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.
1 affected packages
monopd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
monopd | — | — | — | — | — |