Vulnerabilities > Xymon > Xymon > 4.1.1

DATE CVE VULNERABILITY TITLE RISK
2016-04-13 CVE-2016-2056 Command Injection vulnerability in multiple products
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
network
low complexity
xymon debian CWE-77
6.5
2016-04-13 CVE-2016-2055 Information Exposure vulnerability in multiple products
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.
network
low complexity
xymon debian CWE-200
5.0
2016-04-13 CVE-2016-2054 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
network
low complexity
debian xymon CWE-119
7.5
2013-10-11 CVE-2013-4173 Path Traversal vulnerability in Xymon
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a ..
network
low complexity
xymon CWE-22
5.0
2011-04-18 CVE-2011-1716 Cross-Site Scripting vulnerability in Xymon
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
xymon CWE-79
4.3