CVE-2019-13273
- EPSS 0.47%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:35
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
CVE-2019-13274
- EPSS 0.25%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:36
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
CVE-2019-13451
- EPSS 0.96%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:55
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CVE-2019-13452
- EPSS 0.96%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:55
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CVE-2019-13455
- EPSS 1.05%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:56
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
CVE-2019-13484
- EPSS 0.96%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:59
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
CVE-2019-13485
- EPSS 0.96%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:59
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
CVE-2019-13486
- EPSS 0.96%
- Published 27.08.2019 17:15:10
- Last modified 21.11.2024 04:24:59
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
CVE-2015-1430
- EPSS 0.44%
- Published 28.08.2017 15:29:01
- Last modified 20.04.2025 01:37:25
Buffer overflow in xymon 4.3.17-1.
CVE-2016-2058
- EPSS 0.24%
- Published 13.04.2016 16:59:08
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page...