VendorsMono Projectmonoall versions
Vulnerabilities

Mono Project Mono

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2015-2320
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Published 2018-01-08 · Modified
9.8EPSS 0.035
CVE-2023-26314
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.
Published 2023-02-22 · Modified
8.8EPSS 0.010
CVE-2015-2318
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
Published 2018-01-08 · Modified
8.1EPSS 0.020
CVE-2015-2319
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
Published 2018-01-08 · Modified
7.5EPSS 0.032
CVE-2012-3543
mono 2.10.x ASP.NET Web Form Hash collision DoS
Published 2019-11-21 · Modified
7.5EPSS 0.026