SmokePing
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-20015 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2022 | In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown. | ||
| CVE-2017-20147 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2022 | In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to arbitrary PIDs when the service is stopped. | ||
| CVE-2013-4158 | Med | 0.40 | 6.1 | 0.01 | Dec 11, 2019 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) | ||
| CVE-2013-4168 | Med | 0.33 | 6.1 | 0.01 | Nov 1, 2019 | Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. | ||
| CVE-2012-0790 | 0.00 | — | 0.01 | Jan 24, 2012 | Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter. |
- risk 0.49cvss 7.5epss 0.01
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.
- risk 0.42cvss 6.5epss 0.01
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to arbitrary PIDs when the service is stopped.
- risk 0.40cvss 6.1epss 0.01
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
- CVE-2012-0790Jan 24, 2012risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.