CVE List

Id CVE No. Status Description Phase Votes Comments Actions
65519  CVE-2013-5572  Candidate  Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.  Assigned (20130823)  None (candidate not yet proposed)    View
66771  CVE-2013-6824  Candidate  Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.  Assigned (20131119)  None (candidate not yet proposed)    View
51176  CVE-2011-3264  Candidate  Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.  Assigned (20110819)  None (candidate not yet proposed)    View
29567  CVE-2007-6210  Candidate  zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.  Assigned (20071203)  None (candidate not yet proposed)    View
31470  CVE-2008-1353  Candidate  zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.  Assigned (20080317)  None (candidate not yet proposed)    View

Page 20907 of 20943, showing 5 records out of 104715 total, starting on record 104531, ending on 104535

Actions