cbcvebase.

Debian Zoneminder vulnerabilities

75 known vulnerabilities affecting debian/zoneminder.

Total CVEs
75
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH8MEDIUM12LOW50

Vulnerabilities

Page 2 of 4
CVE-2019-8424P3LOWCVSS 9.8fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-8424 [CRITICAL] CVE-2019-8424: zoneminder - ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort paramete... ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed in 1.34.6-1) sid: resolved (fixed in 1.34.6-1) trixie: resolved (fixed in 1.34.6-1)
debian
CVE-2023-26036P3LOWCVSS 8.1fixed in zoneminder 1.36.33+dfsg1-1 (bookworm)2023
CVE-2023-26036 [HIGH] CVE-2023-26036: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling $view, any local file ending in .php can be executed. This is supposed to be mitigated by
debian
CVE-2023-26032P3LOWCVSS 8.9fixed in zoneminder 1.36.33+dfsg1-1 (bookworm)2023
CVE-2023-26032 [HIGH] CVE-2023-26032: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the JWT token was trusted when performing an SQL query to load the user. If an attacker could determine the HASH key u
debian
CVE-2022-39289P3LOWCVSS 9.1fixed in zoneminder 1.36.31+dfsg1-1 (bookworm)2022
CVE-2022-39289 [CRITICAL] CVE-2022-39289: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging
debian
CVE-2016-10205P3HIGHCVSS 7.3fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2016
CVE-2016-10205 [HIGH] CVE-2016-10205: zoneminder - Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote atta... Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie. Scope: local bookworm: resolved (fixed in 1.30.4+dfsg-1) bullseye: resolved (fixed in 1.30.4+dfsg-1) forky: resolved (fixed in 1.30.4+dfsg-1) sid: resolved (fixed in 1.30.4+dfsg-1) trixie: resolved (fixed in 1.30.4+dfsg-1)
debian
CVE-2023-41884P3LOWCVSS 7.1fixed in zoneminder 1.36.35+dfsg1-1 (forky)2023
CVE-2023-41884 [HIGH] CVE-2023-41884: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.36.35+dfsg1-1) sid: resolved (fixed in
debian
CVE-2019-7347P3LOWCVSS 7.5fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7347 [HIGH] CVE-2019-7347: zoneminder - A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through... A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.). Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6
debian
CVE-2019-7346P3LOWCVSS 8.8fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7346 [HIGH] CVE-2019-7346: zoneminder - A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check ... A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed in 1.34.6-1) sid: resolve
debian
CVE-2016-10206P3HIGHCVSS 8.8fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2016
CVE-2016-10206 [HIGH] CVE-2016-10206: zoneminder - Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier a... Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php. Scope: local bookworm: resolved (fixed in 1.30.4+dfsg-1) bullseye: resolved (fixed
debian
CVE-2017-5368P3HIGHCVSS 8.8fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2017
CVE-2017-5368 [HIGH] CVE-2017-5368: zoneminder - ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulne... ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for r
debian
CVE-2020-25730P4HIGHCVSS 8.2fixed in zoneminder 1.34.21-1 (bookworm)2020
CVE-2020-25730 [HIGH] CVE-2020-25730: zoneminder - Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, a... Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php. Scope: local bookworm: resolved (fixed in 1.34.21-1) bullseye: resolved (fixed in 1.34.21-1) forky: resolved (fixed in 1.34.21-1)
debian
CVE-2023-26038P3LOWCVSS 5.4fixed in zoneminder 1.36.33+dfsg1-1 (bookworm)2023
CVE-2023-26038 [MEDIUM] CVE-2023-26038: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via web/ajax/modal.php, where an arbitrary php file path can be passed in the request and loaded. This issue is patched in
debian
CVE-2004-0227P4HIGHCVSS 7.5fixed in zoneminder 1.22.3-1 (bookworm)2004
CVE-2004-0227 [HIGH] CVE-2004-0227: zoneminder - Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote... Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string. Scope: local bookworm: resolved (fixed in 1.22.3-1) bullseye: resolved (fixed in 1.22.3-1) forky: resolved (fixed in 1.22.3-1) sid: resolved (fixed in 1.22.3-1) trixie: resolved (fixed in 1.22.3-1)
debian
CVE-2023-25825P4LOWCVSS 7.7fixed in zoneminder 1.36.33+dfsg1-1 (bookworm)2023
CVE-2023-25825 [HIGH] CVE-2023-25825: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application... ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patch
debian
CVE-2017-5367P4MEDIUMCVSS 6.1fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2017
CVE-2017-5367 [MEDIUM] CVE-2017-5367: zoneminder - Multiple reflected XSS vulnerabilities exist within form and link input paramete... Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, which allows a remote attacker to execute malicious scripts within an authenticated client's browser. The URL is /zm/index.php and sample parameters could include action=login&view=postlogin[XSS] view=consol
debian
CVE-2020-25729P4LOWCVSS 6.1fixed in zoneminder 1.34.21-1 (bookworm)2020
CVE-2020-25729 [MEDIUM] CVE-2020-25729: zoneminder - ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or e... ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. Scope: local bookworm: resolved (fixed in 1.34.21-1) bullseye: resolved (fixed in 1.34.21-1) forky: resolved (fixed in 1.34.21-1) sid: resolved (fixed in 1.34.21-1) trixie: resolved (fixed in 1.34.21-1)
debian
CVE-2019-7331P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7331 [MEDIUM] CVE-2019-7331: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 whi... Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) f
debian
CVE-2019-7326P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7326 [MEDIUM] CVE-2019-7326: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, al... Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (console.php) because proper filtration is omitted. This relates to the index.php?view=monitor Host Name field. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullsey
debian
CVE-2019-7352P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7352 [MEDIUM] CVE-2019-7352: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as... Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) for
debian
CVE-2019-6992P4MEDIUMCVSS 6.1fixed in zoneminder 1.32.3-2 (bookworm)2019
CVE-2019-6992 [MEDIUM] CVE-2019-6992: zoneminder - A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinde... A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI. Scope: local bookworm: resolved (fixed in 1.32.3-2) bullseye: resolved (fixed in 1.32.3-2) forky: resolved (fixed in 1.32.
debian
Debian Zoneminder vulnerabilities | cvebase