Show filters
185 Total Results
Displaying 121-130 of 185
Sort by:
Attacker Value
Unknown

CVE-2018-15709

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2018-15710

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
0
Attacker Value
Unknown

CVE-2018-15711

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
0
Attacker Value
Unknown

CVE-2018-15714

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
0
Attacker Value
Unknown

CVE-2016-8641

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
0
Attacker Value
Unknown

CVE-2018-13441

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-13458

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-13457

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-12501

Disclosure Date: June 16, 2018 (last updated November 26, 2024)
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
0
Attacker Value
Unknown

CVE-2018-10735

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
0