Search CVE reports


Toggle filters

31 – 40 of 70 results


CVE-2018-8733

Medium priority
Not affected

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2017-16834

Medium priority

Not in release

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

1 affected package

pnp4nagios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pnp4nagios Not in release
Show less packages

CVE-2017-14312

High priority
Not affected

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which...

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2017-12847

Low priority
Vulnerable

Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock...

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3 Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2016-0726

Medium priority
Not affected

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2016-6209

Low priority
Vulnerable

Cross-site scripting (XSS) vulnerability in Nagios.

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Not in release Not in release Not affected
nagios3 Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2016-10089

Medium priority
Not affected

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2016-9565

Medium priority
Ignored

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability...

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2016-9566

Medium priority

Some fixes available 4 of 5

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

1 affected package

nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2014-4703

Negligible priority
Ignored

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for...

1 affected package

nagios-plugins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios-plugins
Show less packages