VendorsMonkey Projectmonkey0.9.3
Vulnerabilities

Monkey Project Monkey-Project Monkey 0.9.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2012-4443
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.
Published 2012-10-05 · Modified
6.9EPSS 0.004
CVE-2012-5303
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
Published 2012-10-05 · Modified
6.9EPSS 0.003
CVE-2012-4442
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.
Published 2012-10-05 · Modified
4.7EPSS 0.003
CVE-2014-5336
Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.
Published 2014-08-26 · Modified
4.3EPSS 0.025