Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zabbix HIGH 7.5
CVE-2011-4674

SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbi…

No fix yet
Fix from $1,950 2011-12-02
Zabbix HIGH 7.5
CVE-2010-5049

SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time para…

Fix: after 1.8.1
Fix from $1,950 2011-11-23
Zabbix MEDIUM 5.0
CVE-2011-3263

zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by exec…

Fix: after 1.8.5
Fix from $1,600 2011-08-19
Zabbix MEDIUM 5.0
CVE-2011-3264

Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installa…

Fix: after 1.8.5
Fix from $1,600 2011-08-19
Zabbix MEDIUM 5.0
CVE-2011-3265

popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.

Fix: after 1.8.6
Fix from $1,600 2011-08-19
Zabbix HIGH 7.5
CVE-2010-1277

SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL co…

Patch available
Fix from $1,950 2010-04-06
Zabbix HIGH 9.3
CVE-2009-4502EPSS 22%

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRe…

Fix: after 1.6.6
Fix from $1,950 2009-12-31
Zabbix HIGH 7.5
CVE-2009-4499

SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to …

Fix: after 1.6.7
Fix from $1,950 2009-12-31
Zabbix MEDIUM 6.8
CVE-2009-4498EPSS 32%

The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

Fix: after 1.7.4
Fix from $1,600 2009-12-31
Zabbix MEDIUM 5.0
CVE-2009-4500

The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a craft…

Fix: after 1.4.6
Fix from $1,600 2009-12-31
Zabbix MEDIUM 5.0
CVE-2009-4501EPSS 9%

The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) vi…

Fix: after 1.6.7
Fix from $1,600 2009-12-31
Zabbix HIGH 10.0
CVE-2007-0640

Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."

Fix: after 1.1.4
Fix from $1,950 2007-01-31
Zabbix HIGH 7.5
CVE-2006-6692EPSS 8%

Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execut…

No fix yet
Fix from $1,950 2006-12-21
Zabbix HIGH 7.5
CVE-2006-6693

Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary c…

No fix yet
Fix from $1,950 2006-12-21