RSS   Vulnerabilities for 'Nagios core'   RSS

2018-12-17
 
CVE-2018-18245

CWE-79
 

 
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

 
2018-07-12
 
CVE-2018-13458

CWE-476
 

 
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

 
 
CVE-2018-13457

CWE-476
 

 
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

 
2017-09-11
 
CVE-2017-14312

CWE-264
 

 
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account.

 

 >>> Vendor: Nagios 7 Products
Nagios
Plugins
Remote plug in executor
Nagstamon
Nagios xi
Remote plugin executor
Nagios core


Copyright 2019, cxsecurity.com

 

Back to Top