cbcvebase.

Debian Zabbix vulnerabilities

114 known vulnerabilities affecting debian/zabbix.

Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34

Vulnerabilities

Page 6 of 6
CVE-2010-2790P4MEDIUMCVSS 4.3fixed in zabbix 1:1.8.3-1 (bookworm)2010
CVE-2010-2790 [MEDIUM] CVE-2010-2790: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function ... Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details
debian
CVE-2011-4615P4MEDIUMCVSS 4.3fixed in zabbix 1:1.8.10-1 (bookworm)2011
CVE-2011-4615 [MEDIUM] CVE-2011-4615: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allo... Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php. Scope: local bookworm: resolved (fixed in 1:1.8.10-1) bulls
debian
CVE-2024-42326P4LOWCVSS 4.4fixed in zabbix 1:7.0.5+dfsg-1 (forky)2024
CVE-2024-42326 [MEDIUM] CVE-2024-42326: zabbix - There was discovered a use after free bug in browser.c in the es_browser_get_var... There was discovered a use after free bug in browser.c in the es_browser_get_variant function Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:7.0.5+dfsg-1) sid: resolved (fixed in 1:7.0.5+dfsg-1) trixie: resolved (fixed in 1:7.0.5+dfsg-1)
debian
CVE-2025-27238P4LOWCVSS 2.1fixed in zabbix 1:7.0.22+dfsg-1 (forky)2025
CVE-2025-27238 [LOW] CVE-2025-27238: zabbix - Due to a bug in Zabbix API, the hostprototype.get method lists all host prototyp... Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:7.0.22+dfsg-1) sid: resolved (fixed in 1:7.0.22+dfsg-1) trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
debian
CVE-2024-42332P4LOWCVSS 3.7fixed in zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-42332 [LOW] CVE-2024-42332: zabbix - The researcher is showing that due to the way the SNMP trap log is parsed, an at... The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to know the community/auth details. The attack requires an SNMP item to be configured as text on the target host. Scop
debian
CVE-2024-42325P4LOWCVSS 2.1fixed in zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-42325 [LOW] CVE-2024-42325: zabbix - Zabbix API user.get returns all users that share common group with the calling u... Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.46+dfsg-1+deb11u1) forky: resolved (fixed in 1:7.0.9+dfsg-1) sid: resolved (fixed in 1:7.0.9+dfsg-1) trixie: resolved (fixed in 1:7.0.9+dfsg-1)
debian
CVE-2024-22123P4LOWCVSS 2.7fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22123 [LOW] CVE-2024-22123: zabbix - Setting SMS media allows to set GSM modem file. Later this file is used as Linux... Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI. Scope: local bookwo
debian
CVE-2024-36469P4LOWCVSS 2.3fixed in zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36469 [LOW] CVE-2024-36469: zabbix - Execution time for an unsuccessful login differs when using a non-existing usern... Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.46+dfsg-1+deb11u1) forky: resolved (fixed in 1:7.0.9+dfsg-1) sid: resolved (fixed in 1:7.0.9+dfsg-1) trixie: resolved (fixed in 1:7.0.9+dfsg-1)
debian
CVE-2024-42331P4LOWCVSS 3.3fixed in zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-42331 [LOW] CVE-2024-42331: zabbix - In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a ... In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the browser_push_error method in the src/libs/zbxembed/browser_error.c file. A use-after-free bug can occur at this stage if the wd->browser heap pointer is freed by garbage collection. Scope: lo
debian
CVE-2011-3264P4LOWCVSS 5.0fixed in zabbix 1:1.8.6-1 (bookworm)2011
CVE-2011-3264 [MEDIUM] CVE-2011-3264: zabbix - Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via ... Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message. Scope: local bookworm: resolved (fixed in 1:1.8.6-1) bullseye: resolved (fixed in 1:1.8.6-1) forky: resolved (fixed in 1:1.8.6-1) sid: resolved (fixed in 1:1.8.6-1) trixie: resolved (fixed
debian
CVE-2024-42333P4LOWCVSS 2.7fixed in zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-42333 [LOW] CVE-2024-42333: zabbix - The researcher is showing that it is possible to leak a small amount of Zabbix S... The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.45+dfsg-1+deb11u1) forky: resolved (fixed in 1:7.0.5+dfsg-1) sid: resolved (fixed in 1:7.0.5+dfsg-1) trixie: resolved (fixed in 1:7.0.5+dfsg-1)
debian
CVE-2024-36464P4LOWCVSS 2.7fixed in zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36464 [LOW] CVE-2024-36464: zabbix - When exporting media types, the password is exported in the YAML in plain text. ... When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords. Scope: local bookworm: open bullseye: resolved (fixed in 1:5.0.45+dfsg-1+deb11u
debian
CVE-2024-42329P4LOWCVSS 3.3fixed in zabbix 1:7.0.5+dfsg-1 (forky)2024
CVE-2024-42329 [LOW] CVE-2024-42329: zabbix - The webdriver for the Browser object expects an error object to be initialized w... The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various reasons without an error description and then the wd->error will be NULL and trying to read from it will result in a crash. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:
debian
CVE-2024-22117P4LOWCVSS 2.2fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22117 [LOW] CVE-2024-22117: zabbix - When a URL is added to the map element, it is recorded in the database with sequ... When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map e
debian
Debian Zabbix vulnerabilities | cvebase