← All CVEs

CVE-2010-4254

high · 7.5

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

7.5
CVSS
13.6%
EPSS (exploit prob.)
96th
EPSS percentile
2010-12-06
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
monomonoall versions
novellmoonlight<= 2.3.0
novellmoonlight2.99.0
novellmoonlight2.99.1
novellmoonlight2.99.2
novellmoonlight2.99.7
novellmoonlight2.99.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4254