Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2017-16933 etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gai… Icinga after 2.8.0 Fix from $1,9502017-11-24 HIGH 7.8 CVE-2017-16882 Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account… Icinga after 1.14.0 Fix from $1,9502017-11-18 MEDIUM 6.1 CVE-2015-8010 Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attack… Icinga after 1.13.4 Fix from $1,6002017-03-27 MEDIUM 5.0 CVE-2014-2386 Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vector… Icinga after 1.10.2 Fix from $1,6002014-03-25 MEDIUM 5.0 CVE-2014-1878 Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 befo… Icinga after 4.0.3 Fix from $1,6002014-02-28 MEDIUM 6.8 CVE-2013-7107 Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authenti… Icinga after 1.10.2 Fix from $1,6002014-01-15 MEDIUM 6.5 CVE-2013-7106 Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a de… Icinga after 1.8.4 Fix from $1,6002014-01-15 HIGH 7.5 CVE-2012-3441 The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which … Icinga Mitigation only Fix from $1,9502012-08-25