Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

31 – 40 of 64 results


CVE-2016-6209

Low priority
Vulnerable

Cross-site scripting (XSS) vulnerability in Nagios.

2 affected packages

icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
icinga Not in release Not in release Not in release Not affected Not affected
nagios3 Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2016-10089

Medium priority
Not affected

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

1 affected packages

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios3 Not affected
Show less packages

CVE-2016-9565

Medium priority
Ignored

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability...

1 affected packages

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios3 Not affected
Show less packages

CVE-2016-9566

Medium priority

Some fixes available 4 of 5

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

1 affected packages

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios3 Fixed
Show less packages

CVE-2014-4703

Negligible priority
Ignored

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for...

1 affected packages

nagios-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios-plugins
Show less packages

CVE-2014-4702

Negligible priority
Ignored

The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.

1 affected packages

nagios-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios-plugins Not in release Not in release
Show less packages

CVE-2014-4701

Negligible priority
Ignored

The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.

1 affected packages

nagios-plugins

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios-plugins Not in release Not in release
Show less packages

CVE-2014-4908

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or...

1 affected packages

pnp4nagios

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
pnp4nagios Not in release Not in release
Show less packages

CVE-2014-4907

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled...

1 affected packages

pnp4nagios

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
pnp4nagios Not in release Not in release
Show less packages

CVE-2014-2913

Low priority
Ignored

** DISPUTED ** Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option...

1 affected packages

nagios-nrpe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nagios-nrpe Not affected Not affected Not affected Not affected Not affected
Show less packages