Search CVE reports
11 – 20 of 86 results
CVE-2023-32728
Medium priorityThe Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected | Not affected |
CVE-2023-32727
Medium priorityAn attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Vulnerable | Not affected | Not affected |
CVE-2023-32726
Medium priorityThe vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected | Not affected |
CVE-2023-32725
Medium priorityThe website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Not affected | Not affected | Not affected | Not affected |
CVE-2023-32724
Medium priorityMemory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected | Not affected |
CVE-2023-32723
Medium priorityRequest to LDAP is sent before user permissions are checked.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Not affected | Vulnerable | Not affected | Not affected |
CVE-2023-32722
Medium priorityThe zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Not affected | Not affected | Not affected | Not affected |
CVE-2023-32721
Medium priorityA stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Vulnerable | Not affected | Not affected |
CVE-2023-29453
Medium priorityTemplates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a...
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected | Not affected |
CVE-2023-29458
Medium priorityDuktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an...
1 affected packages
zabbix
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zabbix | Not in release | Vulnerable | Not affected | Not affected | Not affected |