Search CVE reports
61 – 70 of 85 results
CVE-2019-7325
Medium prioritySome fixes available 2 of 8
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Fixed | Not in release | Fixed |
CVE-2019-6992
Medium prioritySome fixes available 2 of 3
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | — | Not affected | Not affected | Not in release | Fixed |
CVE-2019-6991
Medium prioritySome fixes available 2 of 3
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | — | Not affected | Not affected | Not in release | Fixed |
CVE-2019-6990
Medium prioritySome fixes available 2 of 3
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | — | — | — | Not in release | Fixed |
CVE-2019-6777
Medium prioritySome fixes available 2 of 3
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | — | Not affected | Not affected | Not in release | Fixed |
CVE-2018-1000833
Medium priorityZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2018-1000832
Medium priorityZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2017-7203
Medium priorityA Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration of user-supplied data (postLoginQuery) passed to...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-10206
Medium priorityCross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as...
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-10205
Medium prioritySession fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.
1 affected packages
zoneminder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zoneminder | Not affected | Not affected | Not affected | Not in release | Vulnerable |