Lucene search

K

Zabbix Security Vulnerabilities

cve
cve

CVE-2017-2824

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this...

8.1CVSS

8.4AI Score

0.716EPSS

2017-05-24 02:29 PM
67
2
cve
cve

CVE-2016-10134

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in...

9.8CVSS

9.8AI Score

0.045EPSS

2017-02-17 02:59 AM
60
2
cve
cve

CVE-2016-4338

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size...

8.1CVSS

8.3AI Score

0.021EPSS

2017-01-23 09:59 PM
38
cve
cve

CVE-2014-1682

The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login...

8.6AI Score

0.002EPSS

2014-05-08 02:29 PM
29
cve
cve

CVE-2014-1685

The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified...

9.1AI Score

0.002EPSS

2014-05-08 02:29 PM
27
cve
cve

CVE-2012-6086

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid...

9AI Score

0.001EPSS

2014-01-29 06:55 PM
31
cve
cve

CVE-2013-6824

Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user...

9.5AI Score

0.009EPSS

2013-12-19 04:24 AM
34
cve
cve

CVE-2013-1364

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf...

9.2AI Score

0.007EPSS

2013-12-14 05:21 PM
27
cve
cve

CVE-2013-5572

Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source...

8.8AI Score

0.01EPSS

2013-10-01 03:48 AM
42
cve
cve

CVE-2012-3435

SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid...

8.2AI Score

0.002EPSS

2012-08-15 08:55 PM
31
cve
cve

CVE-2011-4615

Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5)...

5.6AI Score

0.003EPSS

2011-12-29 10:55 PM
27
cve
cve

CVE-2011-5027

Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the...

5.5AI Score

0.003EPSS

2011-12-29 10:55 PM
37
cve
cve

CVE-2011-4674

SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid...

8.3AI Score

0.001EPSS

2011-12-02 06:55 PM
22
cve
cve

CVE-2010-5049

SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time...

8.6AI Score

0.002EPSS

2011-11-23 01:55 AM
24
cve
cve

CVE-2011-3263

zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom...

6.4AI Score

0.003EPSS

2011-08-19 09:55 PM
27
cve
cve

CVE-2011-3264

Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error...

6.1AI Score

0.003EPSS

2011-08-19 09:55 PM
26
cve
cve

CVE-2011-3265

popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl...

6.4AI Score

0.006EPSS

2011-08-19 09:55 PM
23
cve
cve

CVE-2011-2904

Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl...

5.5AI Score

0.004EPSS

2011-08-19 09:55 PM
24
cve
cve

CVE-2010-2790

Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select...

5.6AI Score

0.004EPSS

2010-08-05 01:23 PM
28
cve
cve

CVE-2010-1277

SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to...

8.4AI Score

0.006EPSS

2010-04-06 04:30 PM
26
cve
cve

CVE-2009-4498

The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted...

7.3AI Score

0.63EPSS

2009-12-31 06:30 PM
25
cve
cve

CVE-2008-1353

zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or...

6.8AI Score

0.069EPSS

2008-03-17 05:44 PM
19
cve
cve

CVE-2007-6210

zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain...

6.1AI Score

0.0004EPSS

2007-12-04 01:46 AM
37
cve
cve

CVE-2007-0640

Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP...

6.7AI Score

0.005EPSS

2007-01-31 09:28 PM
25
cve
cve

CVE-2006-6693

Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1) zabbix_log and (2) zabbix_syslog...

7.8AI Score

0.008EPSS

2006-12-21 09:28 PM
25
cve
cve

CVE-2006-6692

Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2)...

7.8AI Score

0.008EPSS

2006-12-21 09:28 PM
21
Total number of security vulnerabilities76