← Back

Monkey Project

monkey-project

29 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Monkey
monkey

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 13, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 19, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 19, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
1Monkey Project
1Monkey
Feb 19, 2026
Jan 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to...Show more
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.Show less
1Monkey Project
1Monkey
Nov 21, 2024
Dec 10, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Monkey HTTP Daemon has local security bypass
1Monkey Project
1Monkey
Nov 21, 2024
Dec 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Monkey HTTP Daemon: broken user name authentication
1Monkey Project
1Monkey
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
1Monkey Project
1Monkey
May 6, 2026
Aug 26, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request t...Show more
Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.Show less
1Monkey Project
1Monkey
May 6, 2026
Jun 13, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra...Show more
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.Show less
1Monkey Project
1Monkey
May 6, 2026
Jun 13, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.
1Monkey Project
1Monkey
May 6, 2026
Jun 13, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Range HTTP header.
1Monkey Project
1Monkey
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.
1Monkey Project
1Monkey
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script or HTML via a file name.
1Monkey Project
1Monkey
Apr 29, 2026
Oct 5, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
1Monkey Project
1Monkey
Apr 29, 2026
Oct 5, 2012
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a ra...Show more
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.Show less