Search CVE reports


Toggle filters

61 – 70 of 73 results


CVE-2015-8010

Medium priority
Vulnerable

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

1 affected package

icinga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2014-2386

Medium priority
Ignored

Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table, (2) print_export_link, (3) page_num_selector, or...

1 affected package

icinga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — Not affected
Show less packages

CVE-2014-1878

Low priority

Some fixes available 4 of 14

Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios3 — — — — —
Show less packages

CVE-2013-2214

Low priority
Not affected

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios3 — — — — —
Show less packages

CVE-2013-7107

Low priority
Ignored

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios3 — — — — —
Show less packages

CVE-2013-7106

Medium priority
Ignored

Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to...

1 affected package

icinga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
Show less packages

CVE-2013-7108

Low priority

Some fixes available 4 of 16

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios3 — — — — —
Show less packages

CVE-2013-2029

Medium priority
Ignored

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with...

3 affected packages

icinga, nagios2, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios2 — — — — —
nagios3 — — — — —
Show less packages

CVE-2012-6096

Negligible priority
Ignored

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — —
nagios3 — — — — —
Show less packages

CVE-2012-3441

Medium priority
Ignored

The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.

1 affected package

icinga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — — — Not affected
Show less packages