Moonlight
This hub aggregates every CVE we track for Moonlight, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
9
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting Moonlight.
- CVE-2023-42801Stack buffer overflow due to `strcpy` into fixed size buffer in `extractVersionQuadFromString`7.6
- CVE-2023-42800Buffer overflow due to use of `strcpy` in `performRtspHandshake`8.8
- CVE-2023-42799Buffer overflow due to use of `strcpy` in `parseUrlAddrFromRtspUrlString`8.8
- CVE-2020-11024Man-in-the-middle attack in Moonlight iOS/tvOS6.1
- CVE-2011-0989The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attac...5.8
- CVE-2011-0991Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact vi...6.8
- CVE-2011-0992Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive informati...5.8
- CVE-2011-0990Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a ...5.8
- CVE-2010-4254Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and pos...7.5
Product normalization is registry-driven with AI assist and human review. How it works