Vulnerability index

Browse CVEs

80 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-8426 skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] para… Zoneminder 1.32.3+ Fix from $1,6002019-02-18 HIGH 8.8 CVE-2019-7346 A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button,… Zoneminder after 1.32.3 Fix from $1,9502019-02-04 HIGH 7.5 CVE-2019-7347 A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even af… Zoneminder after 1.32.3 Fix from $1,9502019-02-04 HIGH 7.3 CVE-2019-7350 Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking… Zoneminder after 1.32.3 Fix from $1,9502019-02-04 MEDIUM 6.5 CVE-2019-7351 Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject … Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7340 POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filt… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7341 Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable … Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7342 POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filt… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7343 Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable … Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7344 Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'filter' as it insecurely prin… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7348 Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerabl… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7349 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'n… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7352 Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validatio… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7325 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUES… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7326 Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerabl… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7327 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7328 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7329 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the form action on multiple views utilizes $_SERVER['PHP_SELF'] insecure… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7330 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 's… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7331 Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (moni… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7332 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'e… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7333 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'E… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7334 Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'E… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7335 Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely pri… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7336 Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view _monitor_filters.php contains takes in input from the user … Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7338 Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'group' as it insecurely p… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 MEDIUM 6.1 CVE-2019-7339 POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'leve… Zoneminder after 1.32.3 Fix from $1,6002019-02-04 CRITICAL 9.8 CVE-2019-6991 A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an … Zoneminder after 1.32.3 Fix from $2,3002019-01-28 MEDIUM 6.1 CVE-2019-6992 A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript … Zoneminder after 1.32.3 Fix from $1,6002019-01-28 MEDIUM 5.4 CVE-2019-6990 A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code i… Zoneminder after 1.32.3 Fix from $1,6002019-01-28