peter bassill · operator
$ cve CVE-2010-4254 JSON

CVE-2010-4254 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.6% (pctl 96)

Patch early

A public exploit exists.

Description

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.65% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2010-12-06
Last modified2026-06-16

Affected (2)

VendorProduct
monomono
novellmoonlight

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD