cbcvebase.

Debian Zabbix vulnerabilities

114 known vulnerabilities affecting debian/zabbix.

Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34

Vulnerabilities

Page 5 of 6
CVE-2014-1682P4MEDIUMCVSS 4.0fixed in zabbix 1:2.2.2+dfsg-1 (bookworm)2014
CVE-2014-1682 [MEDIUM] CVE-2014-1682: zabbix - The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2... The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request. Scope: local bookworm: resolved (fixed in 1:2.2.2+dfsg-1) bullseye: resolved (fixed in 1:2.2.2+dfsg-1) forky: resolved (fixed in 1:2.2.2+dfsg-1) sid: resolved (fixed in 1:2.2.2+dfsg
debian
CVE-2023-29449P4MEDIUMCVSS 5.9fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29449 [MEDIUM] CVE-2023-29449: zabbix - JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU... JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over th
debian
CVE-2023-29455P4MEDIUMCVSS 5.4fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-29455 [MEDIUM] CVE-2023-29455: zabbix - Reflected XSS attacks, also known as non-persistent attacks, occur when a malici... Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+de
debian
CVE-2023-32721P4HIGHCVSS 7.6fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-32721 [HIGH] CVE-2023-32721: zabbix - A stored XSS has been found in the Zabbix web application in the Maps element if... A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: resolved (fixed in 1:6.0.23+dfsg-1) sid: resolved (fixed in 1:6.0.23+dfsg-1) trixie: resolved (fixed in 1:6.0.23+dfsg-1)
debian
CVE-2022-24349P4MEDIUMCVSS 4.6fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-24349 [MEDIUM] CVE-2022-24349: zabbix - An authenticated user can create a link with reflected XSS payload for actions’ ... An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiratio
debian
CVE-2022-24919P4LOWCVSS 3.7fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-24919 [LOW] CVE-2022-24919: zabbix - An authenticated user can create a link with reflected Javascript code inside it... An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifi
debian
CVE-2022-35229P4LOWCVSS 3.7fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-35229 [LOW] CVE-2022-35229: zabbix - An authenticated user can create a link with reflected Javascript code inside it... An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Scope: local bookworm: resolved (fixed in 1:6.0.7+dfsg-2) bullseye: resolved (fixed in 1:5.0.44+dfsg-
debian
CVE-2022-35230P4LOWCVSS 3.7fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-35230 [LOW] CVE-2022-35230: zabbix - An authenticated user can create a link with reflected Javascript code inside it... An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Scope: local bookworm: resolved (fixed in 1:6.0.7+dfsg-2) bullseye: resolved (fixed in 1:5.0.44+dfsg-1+d
debian
CVE-2025-27233P4MEDIUMCVSS 5.7fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-27233 [MEDIUM] CVE-2025-27233: zabbix - Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get paramet... Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system. Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 1:7.0.22+dfsg-1) sid: resolved (fixed in 1:7.0.22+dfsg-1) trixie:
debian
CVE-2022-24917P4LOWCVSS 3.7fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-24917 [LOW] CVE-2022-24917: zabbix - An authenticated user can create a link with reflected Javascript code inside it... An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modi
debian
CVE-2022-24918P4LOWCVSS 3.7fixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-24918 [LOW] CVE-2022-24918: zabbix - An authenticated user can create a link with reflected Javascript code inside it... An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modific
debian
CVE-2009-4500P4MEDIUMCVSS 5.0fixed in zabbix 1:1.8-1 (bookworm)2009
CVE-2009-4500 [MEDIUM] CVE-2009-4500: zabbix - The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 all... The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (colon) separator, which triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 1:1.8-1) bullseye: resolved (fixed in 1:1.8-1) forky: resolved (fixed
debian
CVE-2024-42328P4LOWCVSS 3.3fixed in zabbix 1:7.0.5+dfsg-1 (forky)2024
CVE-2024-42328 [LOW] CVE-2024-42328: zabbix - When the webdriver for the Browser object downloads data from a HTTP server, the... When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash. Scope: local bookworm: resolved bullseye: resolved
debian
CVE-2012-6086P4MEDIUMCVSS 4.3fixed in zabbix 1:2.0.7+dfsg-1 (bookworm)2012
CVE-2012-6086 [MEDIUM] CVE-2012-6086: zabbix - libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc... libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. Scope: local bookworm: resolved (fixed in 1:2.0.7+dfsg-1) bullseye: resolved (fixed in 1:2.0.7+d
debian
CVE-2024-22114P4MEDIUMCVSS 4.3fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22114 [MEDIUM] CVE-2024-22114: zabbix - User with no permission to any of the Hosts can access and view host count & oth... User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1) forky: resolved (fixed in 1:7.0.0+dfsg-1) sid: resolved (fixed in 1:7.0.0+dfsg-1) trixie: resolved (fixed in 1:7.0.0+dfsg-1)
debian
CVE-2025-49641P4MEDIUMCVSS 5.1fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-49641 [MEDIUM] CVE-2025-49641: zabbix - A regular Zabbix user with no permission to the Monitoring -> Problems view is s... A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:7.0.22+dfsg-1) sid: resolved (fixed in 1:7.0.22+dfsg-1) trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
debian
CVE-2011-3263P4MEDIUMCVSS 5.0fixed in zabbix 1:1.8.6-1 (bookworm)2011
CVE-2011-3263 [MEDIUM] CVE-2011-3263: zabbix - zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-depen... zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device. Scope: local bookworm: resolved (fixed in 1:1.8.6-1) bullseye: resolved (fixed in 1:1.8.6-1) forky: resolved (fixed in 1:
debian
CVE-2011-5027P4MEDIUMCVSS 4.3fixed in zabbix 1:1.8.10-1 (bookworm)2011
CVE-2011-5027 [MEDIUM] CVE-2011-5027: zabbix - Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote a... Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the profiler. Scope: local bookworm: resolved (fixed in 1:1.8.10-1) bullseye: resolved (fixed in 1:1.8.10-1) forky: resolved (fixed in 1:1.8.10-1) sid: resolved (fixed in 1:1.8.10-1) trixie: resolved (fixed
debian
CVE-2017-2826P4LOWCVSS 3.7fixed in zabbix 1:4.0.0+dfsg-1 (bookworm)2017
CVE-2017-2826 [LOW] CVE-2017-2826: zabbix - An information disclosure vulnerability exists in the iConfig proxy request of Z... An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability. Scope: local book
debian
CVE-2011-2904P4MEDIUMCVSS 4.3fixed in zabbix 1:1.8.6-1 (bookworm)2011
CVE-2011-2904 [MEDIUM] CVE-2011-2904: zabbix - Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 al... Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter. Scope: local bookworm: resolved (fixed in 1:1.8.6-1) bullseye: resolved (fixed in 1:1.8.6-1) forky: resolved (fixed in 1:1.8.6-1) sid: resolved (fixed in 1:1.8.6-1) trixie: resolved (fixed in 1:1.8.6-1
debian
Debian Zabbix vulnerabilities | cvebase