Xymon
xymon
16 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. |
2Debian Xymon2Debian Linux XymonJun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter. |
Buffer overflow in xymon 4.3.17-1. |
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled...Show more |
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue. |
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c. |
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command. |
2Debian Xymon2Debian Linux XymonMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, invo...Show more |
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command. |
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |