Search CVE reports


Toggle filters

11 – 20 of 40 results


CVE-2018-8733

Medium priority
Not affected

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-18245

Low priority
Vulnerable

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

2 affected packages

nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not in release Not in release Not in release Vulnerable
nagios4 Not affected Not affected Not affected Not in release
Show less packages

CVE-2018-10738

Medium priority
Not affected

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not affected
Show less packages

CVE-2018-10737

Medium priority
Not affected

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not affected
Show less packages

CVE-2018-10736

Medium priority
Not affected

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not affected
Show less packages

CVE-2018-10735

Medium priority
Not affected

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not affected
Show less packages

CVE-2017-14312

High priority
Not affected

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which...

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2017-12847

Low priority
Vulnerable

Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock...

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2016-9566

Medium priority

Some fixes available 4 of 5

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2016-9565

Medium priority
Ignored

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability...

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages