Search: "icinga"

57 CVEs found

CVE-2011-2179
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expa...

Published: 2011-06-14
Products: 16
Vendors:
icinga nagios

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML v...

Published: 2011-06-14
Products: 15
Vendors:
icinga

The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via u...

Published: 2012-08-25
Products: 1
Vendors:
icinga

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow rem...

Published: 2013-01-22
Products: 44
Vendors:
icinga nagios
CVE-2013-7106
6.5 MEDIUM

Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitr...

Published: 2014-01-15
Products: 35
Vendors:
icinga
CVE-2013-7107
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspec...

Published: 2014-01-15
Products: 38
Vendors:
icinga
CVE-2013-7108
5.5 MEDIUM

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information ...

Published: 2014-01-15
Products: 71
Vendors:
icinga nagios
CVE-2014-1878
5.0 MEDIUM

Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote atta...

Published: 2014-02-28
Products: 20
Vendors:
icinga nagios
CVE-2014-2386
5.0 MEDIUM

Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table, (2) print_export_li...

Published: 2014-03-25
Products: 5
Vendors:
icinga opensuse

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status...

Published: 2014-11-28
Products: 1
Vendors:
check_diskio_project
CVE-2015-8010
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the ...

Published: 2017-03-27
Products: 3
Vendors:
icinga opensuse_project opensuse

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a ...

Published: 2017-11-18
Products: 1
Vendors:
icinga

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_U...

Published: 2017-11-24
Products: 1
Vendors:
icinga
CVE-2018-6536
5.5 MEDIUM

An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes b...

Published: 2018-02-02
Products: 1
Vendors:
icinga

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering t...

Published: 2018-02-27
Products: 1
Vendors:
icinga

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by...

Published: 2018-02-27
Products: 1
Vendors:
icinga
CVE-2018-6534
6.5 MEDIUM

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause the product to crash.

Published: 2018-02-27
Products: 1
Vendors:
icinga

An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.

Published: 2018-02-27
Products: 1
Vendors:
icinga
CVE-2018-18246
6.5 MEDIUM

Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.

Published: 2018-12-17
Products: 1
Vendors:
icinga
CVE-2018-18247
5.4 MEDIUM

Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.

Published: 2018-12-17
Products: 1
Vendors:
icinga