Monkey-project
Monkey-project Monkey: vulnerabilities and CVEs
Monkey-project Monkey has 29 published vulnerabilities, 9 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs29
Last 12 months9
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63658 | High (7.5) | 1.3% | — | Jan 29, 2026 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63657 | High (7.5) | 1.2% | — | Jan 29, 2026 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63656 | High (7.5) | 1.2% | — | Jan 29, 2026 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63655 | High (7.5) | 8.6% | — | Jan 29, 2026 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63653 | High (7.5) | 1.2% | — | Jan 29, 2026 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63652 | High (7.5) | 1.2% | — | Jan 29, 2026 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63651 | High (7.5) | 1.1% | — | Jan 29, 2026 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63650 | High (7.5) | 1.2% | — | Jan 29, 2026 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. |
| CVE-2025-63649 | High (7.5) | 1.1% | — | Jan 29, 2026 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to… |
| CVE-2013-2183 | High (7.1) | 0.41% | — | Dec 10, 2019 | Monkey HTTP Daemon has local security bypass |
| CVE-2013-2159 | Critical (9.8) | 2.8% | — | Dec 10, 2019 | Monkey HTTP Daemon: broken user name authentication |
| CVE-2013-1771 | High (7.5) | 3.0% | — | Nov 7, 2019 | The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo. |
| CVE-2014-5336 | Medium (4.3) | 2.5% | — | Aug 26, 2014 | Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request… |
| CVE-2013-3843 | Medium (6.8) | 20% | — | Jun 13, 2014 | Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute… |
| CVE-2013-2182 | Medium (5.8) | 5.6% | — | Jun 13, 2014 | The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash. |
| CVE-2013-2163 | Medium (5) | 2.5% | — | Jun 13, 2014 | Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Range HTTP header. |
| CVE-2013-3724 | Medium (5) | 14% | — | Aug 1, 2013 | The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request. |
| CVE-2013-2181 | Medium (4.3) | 2.7% | — | Jul 29, 2013 | Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script or HTML via a file name. |
| CVE-2012-5303 | Medium (6.9) | 0.32% | — | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname. |
| CVE-2012-4442 | Medium (4.7) | 0.31% | — | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a… |
| CVE-2012-4443 | Medium (6.9) | 0.38% | — | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access. |
| CVE-2005-1123 | Medium (5) | 1.6% | — | May 2, 2005 | Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file. |
| CVE-2005-1122 | High (7.5) | 2.7% | — | Apr 14, 2005 | Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded… |
| CVE-2004-0276 | Medium (5) | 3.7% | — | Nov 23, 2004 | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field. |
| CVE-2003-1209 | Medium (5) | 2.4% | — | Dec 31, 2003 | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header. |
| CVE-2003-0218 | High (7.5) | 5.2% | — | May 12, 2003 | Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body. |
| CVE-2002-2154 | Medium (5) | 7.6% | — | Dec 31, 2002 | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. |
| CVE-2002-1663 | Medium (5) | 4.0% | — | Dec 31, 2002 | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value. |
| CVE-2002-1852 | Medium (4.3) | 3.4% | — | Dec 31, 2002 | Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl. |