Show filters
185 Total Results
Displaying 121-130 of 185
Sort by:
Attacker Value
Unknown
CVE-2018-15709
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2018-15710
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
0
Attacker Value
Unknown
CVE-2018-15711
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
0
Attacker Value
Unknown
CVE-2018-15714
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
0
Attacker Value
Unknown
CVE-2016-8641
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
0
Attacker Value
Unknown
CVE-2018-13441
Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown
CVE-2018-13458
Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown
CVE-2018-13457
Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown
CVE-2018-12501
Disclosure Date: June 16, 2018 (last updated November 26, 2024)
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
0
Attacker Value
Unknown
CVE-2018-10735
Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
0