Search CVE reports


Toggle filters

11 – 20 of 65 results


CVE-2020-35269

Medium priority
Needs evaluation

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.

1 affected package

nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-13977

Medium priority
Needs evaluation

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the...

1 affected package

nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Not affected Not affected Needs evaluation Not in release
Show less packages

CVE-2019-3698

Medium priority
Not affected

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially...

2 affected packages

icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not affected
nagios3 Not affected
Show less packages

CVE-2018-8736

High priority
Not affected

A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-8735

High priority
Not affected

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-8734

Medium priority
Not affected

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-8733

Medium priority
Not affected

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-18245

Low priority
Vulnerable

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

2 affected packages

nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not in release Not in release Not in release Vulnerable
nagios4 Not affected Not affected Not affected Not in release
Show less packages

CVE-2018-13458

Medium priority
Ignored

qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

1 affected package

nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Not in release
Show less packages

CVE-2018-13457

Medium priority
Ignored

qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

1 affected package

nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Not in release
Show less packages