Search CVE reports


Toggle filters

11 – 20 of 61 results


CVE-2022-38251

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

3 affected packages

icinga, nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-38250

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

3 affected packages

icinga, nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-38249

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

3 affected packages

icinga, nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-38248

Medium priority
Needs evaluation

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

3 affected packages

icinga, nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-38247

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

3 affected packages

icinga, nagios3, nagios4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-36032

Medium priority
Needs evaluation

ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP’s HTTP server component versions starting with 0.7.0 and prior to 1.7.0, when ReactPHP is processing incoming HTTP cookie values, the...

2 affected packages

icinga-php-thirdparty, icingaweb2-module-reactbundle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga-php-thirdparty Needs evaluation Needs evaluation Not in release Not in release
icingaweb2-module-reactbundle Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2022-2400

Medium priority

Some fixes available 4 of 23

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

3 affected packages

civicrm, icingaweb2, php-dompdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Needs evaluation Needs evaluation Needs evaluation
icingaweb2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
php-dompdf Not in release Fixed Fixed Fixed
Show less packages

CVE-2022-31091

Medium priority
Needs evaluation

Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we...

5 affected packages

civicrm, guzzle, icinga-php-thirdparty, icingaweb2-module-reactbundle, mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Needs evaluation Needs evaluation Needs evaluation
guzzle Not affected Not in release Not in release Not in release
icinga-php-thirdparty Needs evaluation Needs evaluation Not in release Not in release
icingaweb2-module-reactbundle Needs evaluation Needs evaluation Not in release Not in release
mediawiki Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31090

Medium priority
Needs evaluation

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify...

5 affected packages

civicrm, guzzle, icinga-php-thirdparty, icingaweb2-module-reactbundle, mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Needs evaluation Needs evaluation Needs evaluation
guzzle Not affected Not in release Not in release Not in release
icinga-php-thirdparty Needs evaluation Needs evaluation Not in release Not in release
icingaweb2-module-reactbundle Needs evaluation Needs evaluation Not in release Not in release
mediawiki Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24795

Medium priority

Some fixes available 6 of 100

yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB)...

12 affected packages

argyll, burp, centreon-broker, collada2gltf, icinga2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
argyll Needs evaluation Needs evaluation Needs evaluation Needs evaluation
burp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
centreon-broker
collada2gltf Not in release Needs evaluation Needs evaluation
icinga2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libbson Needs evaluation
lnav Needs evaluation Needs evaluation Needs evaluation Needs evaluation
php-mongodb Needs evaluation Needs evaluation Needs evaluation Needs evaluation
r-cran-jsonlite Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ruby-yajl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tulip Not in release Needs evaluation
yajl Not affected Fixed Fixed Fixed
Show all 12 packages Show less packages