Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

61 – 70 of 85 results


CVE-2019-7325

Medium priority

Some fixes available 2 of 8

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Fixed Not in release Fixed
Show less packages

CVE-2019-6992

Medium priority

Some fixes available 2 of 3

A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to...

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not in release Fixed
Show less packages

CVE-2019-6991

Medium priority

Some fixes available 2 of 3

A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not in release Fixed
Show less packages

CVE-2019-6990

Medium priority

Some fixes available 2 of 3

A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to...

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not in release Fixed
Show less packages

CVE-2019-6777

Medium priority

Some fixes available 2 of 3

An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not in release Fixed
Show less packages

CVE-2018-1000833

Medium priority
Vulnerable

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2018-1000832

Medium priority
Vulnerable

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2017-7203

Medium priority
Vulnerable

A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration of user-supplied data (postLoginQuery) passed to...

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-10206

Medium priority
Vulnerable

Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as...

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-10205

Medium priority
Vulnerable

Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.

1 affected packages

zoneminder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zoneminder Not affected Not affected Not affected Not in release Vulnerable
Show less packages