Search CVE reports


Toggle filters

51 – 60 of 125 results


CVE-2023-32725

Medium priority
Ignored

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not in release Not affected Not affected Not affected
Show less packages

CVE-2023-32724

Medium priority
Vulnerable

Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not affected Not in release Vulnerable Not affected Not affected
Show less packages

CVE-2023-32723

Medium priority
Vulnerable

Request to LDAP is sent before user permissions are checked.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not affected Not in release Not affected Vulnerable Not affected
Show less packages

CVE-2023-32722

Medium priority
Ignored

The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not in release Not affected Not affected Not affected
Show less packages

CVE-2023-32721

Medium priority
Vulnerable

A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Needs evaluation Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2023-29453

Medium priority
Vulnerable

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a...

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not affected Not in release Vulnerable Not affected Not affected
Show less packages

CVE-2023-29458

Medium priority
Vulnerable

Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an...

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Needs evaluation Not in release Vulnerable Not affected Not affected
Show less packages

CVE-2023-29457

Medium priority
Vulnerable

Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with...

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Needs evaluation Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2023-29456

Medium priority
Vulnerable

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Needs evaluation Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2023-29455

Medium priority
Vulnerable

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with...

1 affected package

zabbix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zabbix Not affected Not in release Vulnerable Vulnerable Not affected
Show less packages