Search CVE reports
11 – 20 of 72 results
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
3 affected packages
icinga, nagios4, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | Not in release | Not in release | Needs evaluation |
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| nagios3 | — | — | Not in release | Not in release | Needs evaluation |
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
3 affected packages
icinga, nagios4, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | Not in release | Not in release | Needs evaluation |
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| nagios3 | — | — | Not in release | Not in release | Needs evaluation |
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
3 affected packages
icinga, nagios4, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | Not in release | Not in release | Needs evaluation |
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| nagios3 | — | — | Not in release | Not in release | Needs evaluation |
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
3 affected packages
icinga, nagios4, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | Not in release | Not in release | Needs evaluation |
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| nagios3 | — | — | Not in release | Not in release | Needs evaluation |
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.
3 affected packages
icinga, nagios4, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | Not in release | Not in release | Needs evaluation |
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| nagios3 | — | — | Not in release | Not in release | Needs evaluation |
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
1 affected package
nagios4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nagios4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the...
1 affected package
nagios4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nagios4 | Not affected | Not affected | Not affected | Needs evaluation | Not in release |
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.
1 affected package
nagios-nrpe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nagios-nrpe | Not affected | Not affected | Not affected | Not affected | Vulnerable |
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.
1 affected package
nagios-nrpe
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nagios-nrpe | Not affected | Not affected | Not affected | Not affected | Vulnerable |
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially...
2 affected packages
icinga, nagios3
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| icinga | — | — | — | — | Not affected |
| nagios3 | — | — | — | — | Not affected |