Filtered by vendor Zabbix
Subscribe
Total
88 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4500 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 5.0 MEDIUM | N/A |
The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (colon) separator, which triggers a NULL pointer dereference. | |||||
CVE-2009-4499 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 7.5 HIGH | N/A |
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c. | |||||
CVE-2009-4498 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 6.8 MEDIUM | N/A |
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | |||||
CVE-2008-1353 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 4.3 MEDIUM | N/A |
zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero. | |||||
CVE-2007-6210 | 1 Zabbix | 1 Zabbix Agentd | 2024-11-21 | 2.1 LOW | N/A |
zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges. | |||||
CVE-2007-0640 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 10.0 HIGH | N/A |
Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses." | |||||
CVE-2006-6693 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 7.5 HIGH | N/A |
Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1) zabbix_log and (2) zabbix_syslog functions. | |||||
CVE-2006-6692 | 1 Zabbix | 1 Zabbix | 2024-11-21 | 7.5 HIGH | N/A |
Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog. |