彙總 tildeslash 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 緩衝區溢位與拒絕服務 等問題,部分漏洞可能導致 應用程式崩潰,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2020-36969 | M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account. | [email protected] | 8.7 | 0.42% | 2026-01-28 | 2026-06-16 |
| CVE-2020-36968 | M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users. | [email protected] | 7.1 | 0.42% | 2026-01-28 | 2026-06-16 |
| CVE-2022-26563 | An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization. | [email protected] | 8.8 | 0.89% | 2023-07-18 | 2026-06-17 |
| CVE-2019-11455 | A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage). | [email protected] | 8.1 | 3.14% | 2019-04-22 | 2026-06-16 |
| CVE-2019-11393 | An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter. | [email protected] | 9.8 | 2.09% | 2019-04-22 | 2026-06-16 |
| CVE-2004-1899 | The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes. | [email protected] | 5.0 | 1.69% | 2004-12-31 | 2026-06-16 |
| CVE-2004-1898 | Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | [email protected] | 10.0 | 16.57% | 2004-12-31 | 2026-06-16 |
| CVE-2003-1083 | Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request. | [email protected] | 10.0 | 21.11% | 2003-12-31 | 2026-06-16 |
| CVE-2003-1084 | Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field. | [email protected] | 5.0 | 3.69% | 2003-11-24 | 2026-06-16 |