xymon kayıtları
xymon üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %12,5
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-787 Out-of-bounds Write4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2016-2056Silahlaştırılmış | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacterxymon · xymon · CWE-77 | Yüksek8,8 | — | %54,5 | 13 Nis 2016 |
41Planlayın | CVE-2016-2054İstismar yok | Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbixymon · xymon · CWE-119 | Kritik9,8 | — | %5,6 | 13 Nis 2016 |
40Planlayın | CVE-2019-13451İstismar yok | In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.xymon · xymon · CWE-119 | Kritik9,8 | — | %2,4 | 27 Ağu 2019 |
40Planlayın | CVE-2019-13455İstismar yok | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansionxymon · xymon · CWE-787 | Kritik9,8 | — | %2,0 | 27 Ağu 2019 |
40Planlayın | CVE-2019-13486İstismar yok | In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.xymon · xymon · CWE-787 | Kritik9,8 | — | %1,8 | 27 Ağu 2019 |
40Planlayın | CVE-2019-13452İstismar yok | In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.xymon · xymon · CWE-119 | Kritik9,8 | — | %1,8 | 27 Ağu 2019 |
40Planlayın | CVE-2019-13485İstismar yok | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service pxymon · xymon · CWE-787 | Kritik9,8 | — | %1,8 | 27 Ağu 2019 |
40Planlayın | CVE-2019-13484İstismar yok | In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.xymon · xymon · CWE-119 | Kritik9,8 | — | %1,8 | 27 Ağu 2019 |
39İzleyin | CVE-2019-13273İstismar yok | In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script.xymon · xymon · CWE-787 | Kritik9,8 | — | %1,5 | 27 Ağu 2019 |
39İzleyin | CVE-2015-1430İstismar yok | Buffer overflow in xymon 4.3.17-1.xymon · xymon · CWE-119 | Kritik9,8 | — | %1,2 | 28 Ağu 2017 |
35İzleyin | CVE-2016-2055Silahlaştırılmış | xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configurationxymon · xymon · CWE-200 | Yüksek7,5 | — | %17,9 | 13 Nis 2016 |
24İzleyin | CVE-2019-13274İstismar yok | In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.xymon · xymon · CWE-79 | Orta6,1 | — | %0,9 | 27 Ağu 2019 |
21İzleyin | CVE-2013-4173İstismar yok | Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitraxymon · xymon · CWE-22 | Orta5,0 | — | %2,8 | 11 Eki 2013 |
21İzleyin | CVE-2016-2058İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject xymon · xymon · CWE-79 | Orta5,4 | — | %1,2 | 13 Nis 2016 |
17İzleyin | CVE-2011-1716İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web scripxymon · xymon · CWE-79 | Orta4,3 | — | %1,3 | 18 Nis 2011 |
13İzleyin | CVE-2016-2057İstismar yok | lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allowxymon · xymon · CWE-264 | Düşük3,3 | — | %0,5 | 13 Nis 2016 |
- CVE-2016-205651Planlayın
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacter
YüksekCVSS 8,8SilahlaştırılmışEPSS %55xymon · xymon13 Nis 2016
- CVE-2016-205441Planlayın
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbi
KritikCVSS 9,8İstismar yokEPSS %6xymon · xymon13 Nis 2016
- CVE-2019-1345140Planlayın
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1345540Planlayın
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1348640Planlayın
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1345240Planlayın
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1348540Planlayın
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service p
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1348440Planlayın
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2019-1327339İzleyin
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script.
KritikCVSS 9,8İstismar yokEPSS %2xymon · xymon27 Ağu 2019
- CVE-2015-143039İzleyin
Buffer overflow in xymon 4.3.17-1.
KritikCVSS 9,8İstismar yokEPSS %1xymon · xymon28 Ağu 2017
- CVE-2016-205535İzleyin
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration
YüksekCVSS 7,5SilahlaştırılmışEPSS %18xymon · xymon13 Nis 2016
- CVE-2019-1327424İzleyin
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
OrtaCVSS 6,1İstismar yokEPSS %1xymon · xymon27 Ağu 2019
- CVE-2013-417321İzleyin
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitra
OrtaCVSS 5,0İstismar yokEPSS %3xymon · xymon11 Eki 2013
- CVE-2016-205821İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject
OrtaCVSS 5,4İstismar yokEPSS %1xymon · xymon13 Nis 2016
- CVE-2011-171617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web scrip
OrtaCVSS 4,3İstismar yokEPSS %1xymon · xymon18 Nis 2011
- CVE-2016-205713İzleyin
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allow
DüşükCVSS 3,3İstismar yokEPSS %0xymon · xymon13 Nis 2016