Search CVE reports
2041 – 2050 of 47976 results
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication...
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation...
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
1 affected package
zabbix
| Package | 20.04 LTS |
|---|---|
| zabbix | Needs evaluation |
[Unknown description]
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |