Search CVE reports


Toggle filters

111 – 120 of 122 results


CVE-2010-2790

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1)...

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2010-1277

High priority
Ignored

SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2009-4502

Low priority
Ignored

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in...

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2009-4501

Low priority
Ignored

The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL...

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2009-4500

Low priority
Ignored

The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (colon) separator, which triggers a...

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2009-4499

Medium priority
Ignored

SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the...

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2009-4498

High priority
Ignored

The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2008-1353

Low priority
Ignored

zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2007-6210

Medium priority

Some fixes available 2 of 5

zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages

CVE-2007-0640

Medium priority

Some fixes available 2 of 3

Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."

1 affected package

zabbix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix
Show less packages