Show filters
155 Total Results
Displaying 121-130 of 155
Sort by:
Attacker Value
Unknown
CVE-2016-6209
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Nagios.
0
Attacker Value
Unknown
CVE-2008-7313
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
0
Attacker Value
Unknown
CVE-2016-10089
Disclosure Date: February 15, 2017 (last updated November 26, 2024)
Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.
0
Attacker Value
Unknown
CVE-2016-9565
Disclosure Date: December 15, 2016 (last updated November 25, 2024)
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
0
Attacker Value
Unknown
CVE-2016-9566
Disclosure Date: December 15, 2016 (last updated November 25, 2024)
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
0
Attacker Value
Unknown
CVE-2014-4703
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.
0
Attacker Value
Unknown
CVE-2014-4701
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.
0
Attacker Value
Unknown
CVE-2014-4702
Disclosure Date: December 05, 2014 (last updated October 05, 2023)
The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.
0
Attacker Value
Unknown
CVE-2014-4908
Disclosure Date: July 11, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.
0
Attacker Value
Unknown
CVE-2014-4907
Disclosure Date: July 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
0