Monkey-Project / Monkey
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-63658 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via se… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63657 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) v… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63656 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63655 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (Do… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63653 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) vi… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63652 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sen… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63651 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via s… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63650 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via s… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2025-63649 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a D… | HIGH | 7.5 | Jan 29, 2026 |
| CVE-2013-2183 | Monkey HTTP Daemon has local security bypass | HIGH | 7.1 | Dec 10, 2019 |
| CVE-2013-2159 | Monkey HTTP Daemon: broken user name authentication | CRITICAL | 9.8 | Dec 10, 2019 |
| CVE-2013-1771 | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo. | HIGH | 7.5 | Nov 7, 2019 |
| CVE-2014-5336 | Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial o… | MEDIUM | 4.3 | Aug 26, 2014 |
| CVE-2013-3843 | Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to c… | MEDIUM | 6.8 | Jun 13, 2014 |
| CVE-2013-2182 | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrat… | MEDIUM | 5.8 | Jun 13, 2014 |
| CVE-2013-2163 | Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Rang… | MEDIUM | 5.0 | Jun 13, 2014 |
| CVE-2013-3724 | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) v… | MEDIUM | 5.0 | Jul 31, 2013 |
| CVE-2013-2181 | Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script… | MEDIUM | 4.3 | Jul 29, 2013 |
| CVE-2012-5303 | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from… | MEDIUM | 6.9 | Oct 5, 2012 |
| CVE-2012-4442 | Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users… | MEDIUM | 4.7 | Oct 5, 2012 |
| CVE-2012-4443 | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by le… | MEDIUM | 6.9 | Oct 5, 2012 |
| CVE-2002-2154 | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. | MEDIUM | 5.0 | Nov 16, 2005 |
| CVE-2002-1852 | Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to t… | MEDIUM | 4.3 | Jun 28, 2005 |
| CVE-2003-1209 | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-T… | MEDIUM | 5.0 | May 19, 2005 |
| CVE-2002-1663 | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with a… | MEDIUM | 5.0 | May 19, 2005 |
Showing 1 to 25 of 29 CVEs