Search CVE reports


Toggle filters

101 – 110 of 113 results


CVE-2021-36563

Low priority
Fixed

The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Fixed
Show less packages

CVE-2020-24908

Medium priority
Not affected

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not affected
Show less packages

CVE-2014-0243

Medium priority
Ignored

Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not affected
Show less packages

CVE-2017-11507

Medium priority
Vulnerable

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-14955

Medium priority

Some fixes available 2 of 7

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Fixed
Show less packages

CVE-2017-9781

Medium priority

Some fixes available 2 of 8

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Fixed
Show less packages

CVE-2014-2332

Medium priority
Ignored

Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk
Show less packages

CVE-2014-2331

Medium priority
Ignored

Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk
Show less packages

CVE-2014-2330

Medium priority
Ignored

Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests that (1) upload arbitrary snapshots, (2) delete...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk
Show less packages

CVE-2014-2329

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2)...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk
Show less packages