Vulnerabilities (CVE)

Vendor filter

Nagios Subscribe

Filter

56 total CVE
CVE Vendors Products Updated CVSS
CVE-2018-15710 1 Nagios 1 Nagios Xi 2019-01-24 7.2
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
CVE-2018-15708 1 Nagios 1 Nagios Xi 2019-01-24 7.5
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2018-20172 1 Nagios 1 Nagios Xi 2019-01-07 4.3
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
CVE-2018-20171 1 Nagios 1 Nagios Xi 2019-01-07 4.3
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
CVE-2018-18245 2 Nagios, Debian 2 Nagios Core, Debian Linux 2019-01-04 3.5
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
CVE-2016-9566 1 Nagios 1 Nagios 2018-12-25 7.2
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
CVE-2014-1878 2 Nagios, Icinga 2 Nagios, Icinga 2018-12-25 5.0
Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service...
CVE-2013-7205 1 Nagios 1 Nagios 2018-12-25 6.4
Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long...
CVE-2013-7108 2 Nagios, Icinga 2 Nagios, Icinga 2018-12-25 5.5
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of...
CVE-2018-15711 1 Nagios 1 Nagios Xi 2018-12-07 6.5
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
CVE-2018-15712 1 Nagios 1 Nagios Xi 2018-12-06 4.3
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
CVE-2018-15713 1 Nagios 1 Nagios Xi 2018-12-06 3.5
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
CVE-2018-15714 1 Nagios 1 Nagios Xi 2018-12-06 4.3
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
CVE-2018-15709 1 Nagios 1 Nagios Xi 2018-12-06 6.5
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2017-14312 1 Nagios 1 Nagios Core 2018-12-03 7.2
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users...
CVE-2014-2913 3 Nagios, Novell, Opensuse 3 Remote Plugin Executor, Opensuse, Opensuse 2018-10-30 7.5
** DISPUTED ** Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this...
CVE-2013-1362 3 Nagios, Novell, Opensuse 3 Remote Plug In Executor, Opensuse, Opensuse 2018-10-30 7.5
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
CVE-2016-9565 1 Nagios 1 Nagios 2018-10-09 7.5
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of...
CVE-2016-8641 1 Nagios 1 Nagios 2018-10-05 7.2
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the...
CVE-2006-2489 1 Nagios 1 Nagios 2018-10-03 7.5
Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a content length (Content-Length) HTTP header. NOTE: this is a...