Vulnerabilities > Nagios > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-10-23 CVE-2007-5624 Cross-Site Scripting vulnerability in Nagios 2.0.1/2.1.3
Cross-site scripting (XSS) vulnerability in Nagios 2.x before 2.10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts.
network
nagios CWE-79
4.3
2007-10-23 CVE-2007-5623 Buffer Errors vulnerability in Nagios Plugins 1.4.10
Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via crafted snmpget replies.
network
low complexity
nagios CWE-119
5.0
2007-10-04 CVE-2007-5198 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Nagios Plugins
Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading "L" characters.
network
nagios CWE-119
6.8
2006-05-03 CVE-2006-2162 Remote Negative Content-Length Buffer Overflow vulnerability in Nagios 2.0.1/2.1.3
Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content length (Content-Length) HTTP header.
network
low complexity
nagios
5.0