Show filters
81 Total Results
Displaying 71-80 of 81
Sort by:
Attacker Value
Unknown

CVE-2007-5473

Disclosure Date: October 18, 2007 (last updated October 04, 2023)
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.
0
Attacker Value
Unknown

CVE-2007-5247

Disclosure Date: October 06, 2007 (last updated October 04, 2023)
Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server on UDP port 27888 or (2) a PB_U packet to UCON on UDP port 27888, different vectors than CVE-2004-1500. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
0
Attacker Value
Unknown

CVE-2006-6104

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.
0
Attacker Value
Unknown

CVE-2006-5072

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.
0
Attacker Value
Unknown

CVE-2006-2658

Disclosure Date: September 12, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.
0
Attacker Value
Unknown

CVE-2006-1166

Disclosure Date: March 12, 2006 (last updated February 22, 2025)
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.
0
Attacker Value
Unknown

CVE-2006-1046

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.
0
Attacker Value
Unknown

CVE-2005-0509

Disclosure Date: March 14, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
0
Attacker Value
Unknown

CVE-2004-1395

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not "Operation would block."
0
Attacker Value
Unknown

CVE-2004-1500

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
0