Search: "nagios"

320 CVEs found

CVE-2013-3505
4.0 MEDIUM

The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration fi...

Published: 2013-05-08
Products: 1
Vendors:
gwos

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which...

Published: 2013-07-09
Products: 32
Vendors:
nagios opensuse
CVE-2013-2029
6.3 MEDIUM

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary na...

Published: 2013-11-23
Products: 1
Vendors:
redhat
CVE-2013-4214
6.3 MEDIUM

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.

Published: 2013-11-23
Products: 3
Vendors:
redhat nagios

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword paramet...

Published: 2013-11-26
Products: 17
Vendors:
nagios
CVE-2013-6039
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/hostdependencies.php, (2)...

Published: 2013-12-09
Products: 1
Vendors:
nagiosql
CVE-2013-7108
5.5 MEDIUM

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information ...

Published: 2014-01-15
Products: 71
Vendors:
nagios icinga
CVE-2013-7205
6.4 MEDIUM

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory o...

Published: 2014-01-15
Products: 36
Vendors:
nagios
CVE-2013-2214
4.0 MEDIUM

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain se...

Published: 2014-02-10
Products: 39
Vendors:
nagios
CVE-2014-1878
5.0 MEDIUM

Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote atta...

Published: 2014-02-28
Products: 20
Vendors:
icinga nagios
CVE-2013-4215
4.4 MEDIUM

The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a symlink attack on /tmp/ipxping/ipxping.

Published: 2014-05-05
Products: 1
Vendors:
nagios

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to ...

Published: 2014-05-07
Products: 4
Vendors:
nagios opensuse

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

Published: 2014-07-22
Products: 27
Vendors:
elastic

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status...

Published: 2014-11-28
Products: 1
Vendors:
check_diskio_project

The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-47...

Published: 2014-12-05
Products: 1
Vendors:
nagios

The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-47...

Published: 2014-12-05
Products: 1
Vendors:
nagios

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists becau...

Published: 2014-12-05
Products: 1
Vendors:
nagios
CVE-2016-9565
9.8 CRITICAL

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed serve...

Published: 2016-12-15
Products: 1
Vendors:
nagios

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged b...

Published: 2016-12-15
Products: 1
Vendors:
nagios

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

Published: 2017-02-15
Products: 1
Vendors:
nagios