Skip to content
Noroxi

xymon records

16 published records for vendor xymon.

All records

16 records
  • xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacter

    HighCVSS 8.8WeaponizedEPSS 55%

    xymon · xymonApr 13, 2016

  • Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbi

    CriticalCVSS 9.8No exploitEPSS 6%

    xymon · xymonApr 13, 2016

  • In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service p

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script.

    CriticalCVSS 9.8No exploitEPSS 2%

    xymon · xymonAug 27, 2019

  • CVE-2015-1430
    39Monitor

    Buffer overflow in xymon 4.3.17-1.

    CriticalCVSS 9.8No exploitEPSS 1%

    xymon · xymonAug 28, 2017

  • CVE-2016-2055
    35Monitor

    xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration

    HighCVSS 7.5WeaponizedEPSS 18%

    xymon · xymonApr 13, 2016

  • In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    xymon · xymonAug 27, 2019

  • CVE-2013-4173
    21Monitor

    Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitra

    MediumCVSS 5.0No exploitEPSS 3%

    xymon · xymonOct 11, 2013

  • CVE-2016-2058
    21Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject

    MediumCVSS 5.4No exploitEPSS 1%

    xymon · xymonApr 13, 2016

  • CVE-2011-1716
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web scrip

    MediumCVSS 4.3No exploitEPSS 1%

    xymon · xymonApr 18, 2011

  • CVE-2016-2057
    13Monitor

    lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allow

    LowCVSS 3.3No exploitEPSS 0%

    xymon · xymonApr 13, 2016