Search CVE reports


Toggle filters

1 – 10 of 18 results


CVE-2020-36969

Medium priority
Needs evaluation

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update...

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-36968

Medium priority
Needs evaluation

M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and...

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37154

Medium priority
Needs evaluation

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

1 affected package

monitoring-plugins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monitoring-plugins Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-26563

Medium priority

Some fixes available 5 of 6

An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-3325

Medium priority
Not affected

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without...

1 affected package

monitorix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monitorix — — — Not affected Not in release
Show less packages

CVE-2019-11455

Medium priority

Some fixes available 5 of 6

A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also...

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit — — Not affected Not affected Fixed
Show less packages

CVE-2019-11454

Medium priority

Some fixes available 5 of 6

Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of...

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit — — Not affected Not affected Fixed
Show less packages

CVE-2016-7067

Medium priority

Some fixes available 2 of 5

Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.

1 affected package

monit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monit — — — — Not affected
Show less packages

CVE-2013-0340

Medium priority
Ignored

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption),...

40 affected packages

apache2, apr-util, audacity, ayttm, cableswig...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
apr-util — — — — —
audacity — — — — —
ayttm — — — — —
cableswig — — — — —
cadaver — — — — —
celementtree — — — — —
cmake — — — — —
coin3 — — — — —
expat — — — — —
gdcm — — — — —
ghostscript — — — — —
grmonitor — — — — —
insighttoolkit — — — — —
kompozer — — — — —
libparagui1.1 — — — — —
matanza — — — — —
paraview — — — — —
poco — — — — —
python-xml — — — — —
python2.4 — — — — —
python2.5 — — — — —
python2.6 — — — — —
simgear — — — — —
sitecopy — — — — —
smart — — — — —
swish-e — — — — —
tdom — — — — —
texlive-bin — — — — —
tla — — — — —
vnc4 — — — — —
vtk — — — — —
w3c-libwww — — — — —
wbxml2 — — — — —
wxwidgets2.6 — — — — —
wxwidgets2.8 — — — — —
wxwindows2.4 — — — — —
xmlrpc-c — — — — —
xotcl — — — — —
xulrunner — — — — —
Show all 40 packages Show less packages

CVE-2013-0341

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

40 affected packages

apache2, apr-util, audacity, ayttm, cableswig...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
apr-util — — — — —
audacity — — — — —
ayttm — — — — —
cableswig — — — — —
cadaver — — — — —
celementtree — — — — —
cmake — — — — —
coin3 — — — — —
expat — — — — —
gdcm — — — — —
ghostscript — — — — —
grmonitor — — — — —
insighttoolkit — — — — —
kompozer — — — — —
libparagui1.1 — — — — —
matanza — — — — —
paraview — — — — —
poco — — — — —
python-xml — — — — —
python2.4 — — — — —
python2.5 — — — — —
python2.6 — — — — —
simgear — — — — —
sitecopy — — — — —
smart — — — — —
swish-e — — — — —
tdom — — — — —
texlive-bin — — — — —
tla — — — — —
vnc4 — — — — —
vtk — — — — —
w3c-libwww — — — — —
wbxml2 — — — — —
wxwidgets2.6 — — — — —
wxwidgets2.8 — — — — —
wxwindows2.4 — — — — —
xmlrpc-c — — — — —
xotcl — — — — —
xulrunner — — — — —
Show all 40 packages Show less packages