cbcvebase.

Debian Zabbix vulnerabilities

114 known vulnerabilities affecting debian/zabbix.

Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34

Vulnerabilities

Page 4 of 6
CVE-2007-6210P4LOWCVSS 2.1PoCfixed in zabbix 1:1.4.2-4 (bookworm)2007
CVE-2007-6210 [LOW] CVE-2007-6210: zabbix - zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid... zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges. Scope: local bookworm: resolved (fixed in 1:1.4.2-4) bullseye: resolved (fixed in 1:1.4.2-4) forky: resolved (fixed in 1:1.4.2-4) sid: resolved (fixed in 1:1.4.2-4) trixie: resolved (fixed in 1:1.4.2-4)
debian
CVE-2023-29458P4MEDIUMCVSS 5.9fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29458 [MEDIUM] CVE-2023-29458: zabbix - Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portabilit... Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: resolved (fixed in 1:6
debian
CVE-2025-49643P4MEDIUMCVSS 6.0fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-49643 [MEDIUM] CVE-2025-49643: zabbix - An authenticated Zabbix user (including Guest) is able to cause disproportionate... An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:7.0.22+dfsg-1) sid: resolved (fixed in 1:7.0.22+dfsg-1) trixie: resolved (fixed in 1:7.0.22
debian
CVE-2007-0640P4CRITICALCVSS 10.0fixed in zabbix 1:1.1.4-8 (bookworm)2007
CVE-2007-0640 [CRITICAL] CVE-2007-0640: zabbix - Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors rel... Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses." Scope: local bookworm: resolved (fixed in 1:1.1.4-8) bullseye: resolved (fixed in 1:1.1.4-8) forky: resolved (fixed in 1:1.1.4-8) sid: resolved (fixed in 1:1.1.4-8) trixie: resolved (fixed in 1:1.1.4-8)
debian
CVE-2013-1364P4MEDIUMCVSS 5.0fixed in zabbix 1:2.0.4+dfsg-2 (bookworm)2013
CVE-2013-1364 [MEDIUM] CVE-2013-1364: zabbix - The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows r... The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter. Scope: local bookworm: resolved (fixed in 1:2.0.4+dfsg-2) bullseye: resolved (fixed in 1:2.0.4+dfsg-2) forky: resolved (fixed in 1:2.0.4+dfsg-2) sid: resolved (fixed in 1:2.0.4+dfsg-2) trixie: resolved (fixed in 1:2.0.4
debian
CVE-2011-3265P4MEDIUMCVSS 5.0fixed in zabbix 1:1.8.9-1 (bookworm)2011
CVE-2011-3265 [MEDIUM] CVE-2011-3265: zabbix - popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of... popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter. Scope: local bookworm: resolved (fixed in 1:1.8.9-1) bullseye: resolved (fixed in 1:1.8.9-1) forky: resolved (fixed in 1:1.8.9-1) sid: resolved (fixed in 1:1.8.9-1) trixie: resolved (fixed in 1:1.8.9-1)
debian
CVE-2006-6693P4MEDIUMCVSS 7.5fixed in zabbix 1:1.1.2-4 (bookworm)2006
CVE-2006-6693 [HIGH] CVE-2006-6693: zabbix - Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a d... Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1) zabbix_log and (2) zabbix_syslog functions. Scope: local bookworm: resolved (fixed in 1:1.1.2-4) bullseye: resolved (fixed in 1:1.1.2-4) forky: resolved (fixed in 1:1.1.2-4) sid: resolved (f
debian
CVE-2019-15132P4MEDIUMCVSS 5.3fixed in zabbix 1:5.0.7+dfsg-1 (bookworm)2019
CVE-2019-15132 [MEDIUM] CVE-2019-15132: zabbix - Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is p... Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php. Scope: lo
debian
CVE-2014-1685P4MEDIUMCVSS 5.5fixed in zabbix 1:2.2.2+dfsg-1 (bookworm)2014
CVE-2014-1685 [MEDIUM] CVE-2014-1685: zabbix - The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x befor... The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.2.2+dfsg-1) bullseye: resolved (fixed in 1:2.2.2+dfsg-1) forky: resolved (fixed in 1:2.2.2+dfsg-1) sid: resolved (fixed in 1:2.2.2+df
debian
CVE-2022-40626P4MEDIUMCVSS 4.8fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-40626 [MEDIUM] CVE-2022-40626: zabbix - An unauthenticated user can create a link with reflected Javascript code inside ... An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend. Scope: local bookworm: resolved (fixed in 1:6.0.7+dfsg-2) bullseye: resolved forky: resolved (fixed in 1:6.0.7+dfsg-2) sid: resol
debian
CVE-2024-45700P4MEDIUMCVSS 6.0fixed in zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-45700 [MEDIUM] CVE-2024-45700: zabbix - Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource ... Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash. Scope: local bookworm: open bullseye: resolved (fix
debian
CVE-2026-23919P4HIGHCVSS 7.1fixed in zabbix 1:7.0.22+dfsg-1 (forky)2026
CVE-2026-23919 [HIGH] CVE-2026-23919: zabbix - For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts... For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but plea
debian
CVE-2025-27231P4MEDIUMCVSS 4.3fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-27231 [MEDIUM] CVE-2025-27231: zabbix - The LDAP 'Bind password' value cannot be read after saving, but a Super Admin ac... The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:7.0.22+dfsg-1) sid: resolved (fixed in 1:7.0.22+dfsg-1) trixie: resolved (f
debian
CVE-2022-23133P4MEDIUMCVSS 6.3fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-23133 [MEDIUM] CVE-2022-23133: zabbix - An authenticated user can create a hosts group from the configuration with XSS p... An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users
debian
CVE-2023-29457P4MEDIUMCVSS 6.3fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29457 [MEDIUM] CVE-2023-29457: zabbix - Reflected XSS attacks, occur when a malicious script is reflected off a web appl... Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: r
debian
CVE-2023-29456P4MEDIUMCVSS 5.7fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29456 [MEDIUM] CVE-2023-29456: zabbix - URL validation scheme receives input from a user and then parses it to identify ... URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: resolved (fixed in 1:6.0.23+dfsg-1) sid: resolved (fixed in 1:6.0.23+dfsg-1) trixie:
debian
CVE-2024-22119P4MEDIUMCVSS 5.5fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22119 [MEDIUM] CVE-2024-22119: zabbix - The cause of vulnerability is improper validation of form input field “Name” on ... The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: resolved (fixed in 1:6.0.24+dfsg-1) sid: resolved (fixed in 1:6.0.24+dfsg-1) trixie: resolved (fixed in 1:6.0.24+dfsg-1)
debian
CVE-2023-29454P4MEDIUMCVSS 5.4fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29454 [MEDIUM] CVE-2023-29454: zabbix - Stored or persistent cross-site scripting (XSS) is a type of XSS where the attac... Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages. Scope: local bookworm: open bullseye: re
debian
CVE-2024-45699P4HIGHCVSS 7.5fixed in zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-45699 [HIGH] CVE-2024-45699: zabbix - The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scrip... The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's
debian
CVE-2016-10742P4LOWCVSS 6.1fixed in zabbix 1:3.0.17+dfsg-1 (bookworm)2016
CVE-2016-10742 [MEDIUM] CVE-2016-10742: zabbix - Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1,... Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter. Scope: local bookworm: resolved (fixed in 1:3.0.17+dfsg-1) bullseye: resolved (fixed in 1:3.0.17+dfsg-1) forky: resolved (fixed in 1:3.0.17+dfsg-1) sid: resolved (fixed in 1:3.0.17+dfsg-1) trixie: resol
debian
Debian Zabbix vulnerabilities | cvebase