- EPSS 4.57%
- Veröffentlicht 31.12.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL pointer dereference, as demonstrate...
- EPSS 0.73%
- Veröffentlicht 31.12.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (colon) separator, which triggers a NULL pointer derefe...
CVE-2009-4499
- EPSS 0.83%
- Veröffentlicht 31.12.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id fu...
CVE-2009-4498
- EPSS 71.78%
- Veröffentlicht 31.12.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
CVE-2008-1353
- EPSS 5.86%
- Veröffentlicht 17.03.2008 17:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.
- EPSS 0.92%
- Veröffentlicht 31.01.2007 21:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."
CVE-2006-6692
- EPSS 5.99%
- Veröffentlicht 21.12.2006 21:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log...
CVE-2006-6693
- EPSS 0.99%
- Veröffentlicht 21.12.2006 21:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1) zabbix_log and (2) zabbix_syslog functions.