Debian Zabbix vulnerabilities
114 known vulnerabilities affecting debian/zabbix.
Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34
Vulnerabilities
Page 3 of 6
CVE-2023-32723P3HIGHCVSS 8.5fixed in zabbix 1:5.0.0+dfsg-1 (bookworm)2023
CVE-2023-32723 [HIGH] CVE-2023-32723: zabbix - Request to LDAP is sent before user permissions are checked.
Request to LDAP is sent before user permissions are checked.
Scope: local
bookworm: resolved (fixed in 1:5.0.0+dfsg-1)
bullseye: resolved (fixed in 1:5.0.0+dfsg-1)
forky: resolved (fixed in 1:5.0.0+dfsg-1)
sid: resolved (fixed in 1:5.0.0+dfsg-1)
trixie: resolved (fixed in 1:5.0.0+dfsg-1)
debian
CVE-2023-32725P3CRITICALCVSS 9.6fixed in zabbix 1:6.0.23+dfsg-1 (forky)2023
CVE-2023-32725 [CRITICAL] CVE-2023-32725: zabbix - The website configured in the URL widget will receive a session cookie when test...
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in
debian
CVE-2013-5572P4LOWCVSS 3.5PoCfixed in zabbix 1:2.2.2+dfsg-1 (bookworm)2013
CVE-2013-5572 [LOW] CVE-2013-5572: zabbix - Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind passwor...
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Scope: local
bookworm: resolved (fixed in 1:2.2.2+dfsg-1)
bullseye: resolved (fixed in 1:2.2.2+dfsg-1)
forky: resolved (fixed in 1:2.2.2+dfsg-1)
sid: resolved (fixed in 1:2.2.2+dfsg-1)
debian
CVE-2023-29450P3HIGHCVSS 8.5fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29450 [HIGH] CVE-2023-29450: zabbix - JavaScript pre-processing can be used by the attacker to gain access to the file...
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resol
debian
CVE-2023-32727P3MEDIUMCVSS 6.8fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-32727 [MEDIUM] CVE-2023-32727: zabbix - An attacker who has the privilege to configure Zabbix items can use function icm...
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resol
debian
CVE-2024-36460P3HIGHCVSS 8.1fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36460 [HIGH] CVE-2024-36460: zabbix - The front-end audit log allows viewing of unprotected plaintext passwords, where...
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
debian
CVE-2024-36468P3LOWCVSS 3.0fixed in zabbix 1:7.0.3+dfsg-1 (forky)2024
CVE-2024-36468 [LOW] CVE-2024-36468: zabbix - The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_hand...
The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from session->securityEngineID to local_record.engineid without proper bounds checking.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:7.0.3+dfsg-1)
sid: resolved (
debian
CVE-2025-27234P3HIGHCVSS 7.3fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2025
CVE-2025-27234 [HIGH] CVE-2025-27234: zabbix - Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get paramet...
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
Scope: local
bookworm: resolved (fixed in 1:6.0.7+dfsg-2)
bullseye: resolved (fixed in 1:5.0.47+dfsg-0+deb11u1)
forky: resolved (fixed in 1:6.0.7+dfsg-2
debian
CVE-2023-32726P3LOWCVSS 3.9fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-32726 [LOW] CVE-2023-32726: zabbix - The vulnerability is caused by improper check for check if RDLENGTH does not ove...
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.24+dfsg-1)
sid: resolved (fixed in 1:6.0.24+dfsg-1)
trixie: resolved (fixed in 1:6.0.24+dfsg-1)
debian
CVE-2010-1277P3HIGHCVSS 7.5fixed in zabbix 1:1.8.2-1 (bookworm)2010
CVE-2010-1277 [HIGH] CVE-2010-1277: zabbix - SQL injection vulnerability in the user.authenticate method in the API in Zabbix...
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
Scope: local
bookworm: resolved (fixed in 1:1.8.2-1)
bullseye: resolved (fixed in 1:1.8.2-1)
forky: resolved (fixed in 1:1.8.2-1)
sid: resolved (fixed in 1:1.8
debian
CVE-2010-5049P3HIGHCVSS 7.5fixed in zabbix 1:1.8.2-1 (bookworm)2010
CVE-2010-5049 [HIGH] CVE-2010-5049: zabbix - SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows rem...
SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.
Scope: local
bookworm: resolved (fixed in 1:1.8.2-1)
bullseye: resolved (fixed in 1:1.8.2-1)
forky: resolved (fixed in 1:1.8.2-1)
sid: resolved (fixed in 1:1.8.2-1)
trixie: resolved (fixed in 1:1.8.2-1)
debian
CVE-2022-23132P3LOWCVSS 3.3fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-23132 [LOW] CVE-2022-23132: zabbix - During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use t...
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
Scope: local
bookworm: resolved (fixed in 1:6.0.7+dfsg-2)
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
debian
CVE-2017-2825P3HIGHCVSS 7.0fixed in zabbix 1:3.0.7+dfsg-3 (bookworm)2017
CVE-2017-2825 [HIGH] CVE-2017-2825: zabbix - In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trappe...
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1:3.0.7+dfsg-3)
bullsey
debian
CVE-2008-1353P4LOWCVSS 4.3PoCfixed in zabbix 1:1.4.5-1 (bookworm)2008
CVE-2008-1353 [MEDIUM] CVE-2008-1353: zabbix - zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of servi...
zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.
Scope: local
bookworm: resolved (fixed in 1:1.4.5-1)
bullseye: resolved (fixed in 1:1.4.5-1)
forky: resolved (fixed in 1:1.4.5-1)
sid: resolved (fixed in
debian
CVE-2008-7220P3LOWCVSS 7.5fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2008
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before...
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
Scope: local
bullseye: resolved (fixed in 1:1.6.2.0~rc3-1)
sid: resolved (fixed in 1:1.6.2.0~rc3-1)
debian
CVE-2023-32722P3CRITICALCVSS 9.6fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-32722 [CRITICAL] CVE-2023-32722: zabbix - The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsi...
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
debian
CVE-2024-36462P3LOWCVSS 7.5fixed in zabbix 1:7.0.1+dfsg-1 (forky)2024
CVE-2024-36462 [HIGH] CVE-2024-36462: zabbix - Uncontrolled resource consumption refers to a software vulnerability where a att...
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance of the affected system.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolve
debian
CVE-2025-27236P3LOWCVSS 2.1fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-27236 [LOW] CVE-2025-27236: zabbix - A regular Zabbix user can search other users in their user group via Zabbix API ...
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.
debian
CVE-2023-29451P3MEDIUMCVSS 4.7fixed in zabbix 1:6.0.23+dfsg-1 (forky)2023
CVE-2023-29451 [MEDIUM] CVE-2023-29451: zabbix - Specially crafted string can cause a buffer overrun in the JSON parser library l...
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
debian
CVE-2013-7484P3HIGHCVSS 7.5fixed in zabbix 1:5.0.0+dfsg-1 (bookworm)2013
CVE-2013-7484 [HIGH] CVE-2013-7484: zabbix - Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
Scope: local
bookworm: resolved (fixed in 1:5.0.0+dfsg-1)
bullseye: resolved (fixed in 1:5.0.0+dfsg-1)
forky: resolved (fixed in 1:5.0.0+dfsg-1)
sid: resolved (fixed in 1:5.0.0+dfsg-1)
trixie: resolved (fixed in 1:5.0.0+dfsg-1)
debian