« Volver al listado

CVE-2010-4254

Estado: ModificadaAlta (7.5)—

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-4254",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-12-06T13:44:54.157",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42373",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42877",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.exploit-db.com/exploits/15974",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerability",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/45051",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0076",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=654136",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=655847",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcac",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42373",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42877",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/15974",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerability",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/45051",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0076",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=654136",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=655847",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcac",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call."
    },
    {
      "lang": "es",
      "value": "Mono, cuando Moonlight en versiones anteriores a la 2.3.0.1 o 2.99.x anteriores a la 2.99.0.10 es utilizado, no valida apropiadamente los argumentos a los métodos genéricos. Lo que permite a atacantes remotos evitar las restricciones genéricas y posiblemente ejecutar código arbitrario a través de una llamada a un método modificado."
    }
  ],
  "lastModified": "2026-06-16T23:24:26.833",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mono:mono:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E062208D-082B-4BFD-85CA-3848ECE6F8CF"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:moonlight:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F4B24CA-B511-49A1-A3F6-5128279D1339",
              "versionEndIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:novell:moonlight:2.99.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF483675-722E-42AF-9698-4BFBE4987ADE"
            },
            {
              "criteria": "cpe:2.3:a:novell:moonlight:2.99.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CB09C96-4186-4828-AF42-BDAB1D52C510"
            },
            {
              "criteria": "cpe:2.3:a:novell:moonlight:2.99.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "925AFBDD-F52F-4D71-B201-1002B0B2924B"
            },
            {
              "criteria": "cpe:2.3:a:novell:moonlight:2.99.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD682A37-02C5-481B-A1EB-CD8452757E7B"
            },
            {
              "criteria": "cpe:2.3:a:novell:moonlight:2.99.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE13D028-0948-4C9C-9EF4-56956ED64006"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}