Xymon 4.0.3

CPE Details

Xymon 4.0.3
4.0.3
2011-04-19
12h33 +00:00
2011-04-22
14h26 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:xymon:xymon:4.0.3:*:*:*:*:*:*:*

Informations

Vendor

xymon

Product

xymon

Version

4.0.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-13273 2019-08-27 14h52 +00:00 In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
9.8
Critical
CVE-2019-13274 2019-08-27 14h49 +00:00 In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
6.1
Medium
CVE-2019-13451 2019-08-27 14h37 +00:00 In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
9.8
Critical
CVE-2019-13452 2019-08-27 14h31 +00:00 In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
9.8
Critical
CVE-2019-13455 2019-08-27 14h28 +00:00 In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in acknowledge.c.
9.8
Critical
CVE-2019-13484 2019-08-27 14h26 +00:00 In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.
9.8
Critical
CVE-2019-13485 2019-08-27 14h25 +00:00 In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
9.8
Critical
CVE-2019-13486 2019-08-27 14h01 +00:00 In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.
9.8
Critical
CVE-2013-4173 2013-10-11 22h00 +00:00 Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command.
5
CVE-2011-1716 2011-04-18 16h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3