xymon records
16 published records for vendor xymon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 12.5%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-787 Out-of-bounds Write4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2016-2056Weaponized | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacterxymon · xymon · CWE-77 | High8.8 | — | 54.5% | Apr 13, 2016 |
41Plan | CVE-2016-2054No exploit | Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbixymon · xymon · CWE-119 | Critical9.8 | — | 5.6% | Apr 13, 2016 |
40Plan | CVE-2019-13451No exploit | In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.xymon · xymon · CWE-119 | Critical9.8 | — | 2.4% | Aug 27, 2019 |
40Plan | CVE-2019-13455No exploit | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansionxymon · xymon · CWE-787 | Critical9.8 | — | 2.0% | Aug 27, 2019 |
40Plan | CVE-2019-13486No exploit | In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.xymon · xymon · CWE-787 | Critical9.8 | — | 1.8% | Aug 27, 2019 |
40Plan | CVE-2019-13452No exploit | In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.xymon · xymon · CWE-119 | Critical9.8 | — | 1.8% | Aug 27, 2019 |
40Plan | CVE-2019-13485No exploit | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service pxymon · xymon · CWE-787 | Critical9.8 | — | 1.8% | Aug 27, 2019 |
40Plan | CVE-2019-13484No exploit | In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.xymon · xymon · CWE-119 | Critical9.8 | — | 1.8% | Aug 27, 2019 |
39Monitor | CVE-2019-13273No exploit | In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script.xymon · xymon · CWE-787 | Critical9.8 | — | 1.5% | Aug 27, 2019 |
39Monitor | CVE-2015-1430No exploit | Buffer overflow in xymon 4.3.17-1.xymon · xymon · CWE-119 | Critical9.8 | — | 1.2% | Aug 28, 2017 |
35Monitor | CVE-2016-2055Weaponized | xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configurationxymon · xymon · CWE-200 | High7.5 | — | 17.9% | Apr 13, 2016 |
24Monitor | CVE-2019-13274No exploit | In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.xymon · xymon · CWE-79 | Medium6.1 | — | 0.9% | Aug 27, 2019 |
21Monitor | CVE-2013-4173No exploit | Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitraxymon · xymon · CWE-22 | Medium5.0 | — | 2.8% | Oct 11, 2013 |
21Monitor | CVE-2016-2058No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject xymon · xymon · CWE-79 | Medium5.4 | — | 1.2% | Apr 13, 2016 |
17Monitor | CVE-2011-1716No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web scripxymon · xymon · CWE-79 | Medium4.3 | — | 1.3% | Apr 18, 2011 |
13Monitor | CVE-2016-2057No exploit | lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allowxymon · xymon · CWE-264 | Low3.3 | — | 0.5% | Apr 13, 2016 |
- CVE-2016-205651Plan
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacter
HighCVSS 8.8WeaponizedEPSS 55%xymon · xymonApr 13, 2016
- CVE-2016-205441Plan
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbi
CriticalCVSS 9.8No exploitEPSS 6%xymon · xymonApr 13, 2016
- CVE-2019-1345140Plan
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1345540Plan
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1348640Plan
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1345240Plan
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1348540Plan
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service p
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1348440Plan
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2019-1327339Monitor
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script.
CriticalCVSS 9.8No exploitEPSS 2%xymon · xymonAug 27, 2019
- CVE-2015-143039Monitor
Buffer overflow in xymon 4.3.17-1.
CriticalCVSS 9.8No exploitEPSS 1%xymon · xymonAug 28, 2017
- CVE-2016-205535Monitor
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration
HighCVSS 7.5WeaponizedEPSS 18%xymon · xymonApr 13, 2016
- CVE-2019-1327424Monitor
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
MediumCVSS 6.1No exploitEPSS 1%xymon · xymonAug 27, 2019
- CVE-2013-417321Monitor
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitra
MediumCVSS 5.0No exploitEPSS 3%xymon · xymonOct 11, 2013
- CVE-2016-205821Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject
MediumCVSS 5.4No exploitEPSS 1%xymon · xymonApr 13, 2016
- CVE-2011-171617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web scrip
MediumCVSS 4.3No exploitEPSS 1%xymon · xymonApr 18, 2011
- CVE-2016-205713Monitor
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allow
LowCVSS 3.3No exploitEPSS 0%xymon · xymonApr 13, 2016