VYPR

rpm package

opensuse/nagios&distro=openSUSE Leap 15.1

pkg:rpm/opensuse/nagios&distro=openSUSE%20Leap%2015.1

Vulnerabilities (5)

  • CVE-2019-3698Feb 28, 2020
    affected < 4.4.5-lp151.5.4.1fixed 4.4.5-lp151.5.4.1

    UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue

  • CVE-2018-18245Dec 17, 2018
    affected < 4.4.5-lp151.5.4.1fixed 4.4.5-lp151.5.4.1

    Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

  • CVE-2018-13458Jul 12, 2018
    affected < 4.4.5-lp151.5.4.1fixed 4.4.5-lp151.5.4.1

    qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

  • CVE-2018-13457Jul 12, 2018
    affected < 4.4.5-lp151.5.4.1fixed 4.4.5-lp151.5.4.1

    qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

  • CVE-2018-13441Jul 12, 2018
    affected < 4.4.5-lp151.5.4.1fixed 4.4.5-lp151.5.4.1

    qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.