Search CVE reports
31 – 40 of 107 results
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Needs evaluation | Not affected |
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected |
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Not affected | Not affected | Not affected |
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected |
Request to LDAP is sent before user permissions are checked.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Not affected | Vulnerable | Not affected |
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Not affected | Not affected | Not affected |
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Vulnerable | Not affected |
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an...
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected |
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with...
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Vulnerable | Not affected |
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
1 affected package
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
zabbix | Not in release | Vulnerable | Vulnerable | Not affected |