cbcvebase.

Debian Zoneminder vulnerabilities

75 known vulnerabilities affecting debian/zoneminder.

Total CVEs
75
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH8MEDIUM12LOW50

Vulnerabilities

Page 4 of 4
CVE-2019-7330P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7330 [MEDIUM] CVE-2019-7330: zoneminder - Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowi... Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed in 1.34.6-1)
debian
CVE-2019-7339P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7339 [MEDIUM] CVE-2019-7339: zoneminder - POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing ... POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'level' parameter value in the view log (log.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed in 1.34.6-1) sid: r
debian
CVE-2019-7343P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7343 [MEDIUM] CVE-2019-7343: zoneminder - Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allo... Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[Method]' parameter value in the view monitor (monitor.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved
debian
CVE-2019-7333P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7333 [MEDIUM] CVE-2019-7333: zoneminder - Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowi... Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Exportfile' parameter value in the view download (download.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed i
debian
CVE-2019-7341P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7341 [MEDIUM] CVE-2019-7341: zoneminder - Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allo... Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[LinkedMonitors]' parameter value in the view monitor (monitor.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: r
debian
CVE-2019-7334P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7334 [MEDIUM] CVE-2019-7334: zoneminder - Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowi... Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Exportfile' parameter value in the view export (export.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed in 1.
debian
CVE-2019-7344P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7344 [MEDIUM] CVE-2019-7344: zoneminder - Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execu... Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'filter' as it insecurely prints the 'filter[Name]' (aka Filter name) value on the web page without applying any proper filtration. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky: resolved (fixed
debian
CVE-2019-7349P4LOWCVSS 6.1fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7349 [MEDIUM] CVE-2019-7349: zoneminder - Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowi... Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[V4LCapturesPerFrame]' parameter value in the view monitor (monitor.php) because proper filtration is omitted. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: resolved (fixed in 1.34.6-1) forky
debian
CVE-2016-10201P4MEDIUMCVSS 6.1fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2016
CVE-2016-10201 [MEDIUM] CVE-2016-10201: zoneminder - Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows r... Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php. Scope: local bookworm: resolved (fixed in 1.30.4+dfsg-1) bullseye: resolved (fixed in 1.30.4+dfsg-1) forky: resolved (fixed in 1.30.4+dfsg-1) sid: resolved (fixed
debian
CVE-2016-10202P4MEDIUMCVSS 6.1fixed in zoneminder 1.30.4+dfsg-1 (bookworm)2016
CVE-2016-10202 [MEDIUM] CVE-2016-10202: zoneminder - Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows r... Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php. Scope: local bookworm: resolved (fixed in 1.30.4+dfsg-1) bullseye: resolved (fixed in 1.30.4+dfsg-1) forky: resolved (fixed in 1.30.4+dfsg-1) sid: resolved (fixed in 1.30.4+dfsg-1) trixie: resolve
debian
CVE-2008-6755P4LOWCVSS 5.0fixed in zoneminder 1.24.1-1 (bookworm)2008
CVE-2008-6755 [MEDIUM] CVE-2008-6755: zoneminder - ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache ... ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script. Scope: local bookworm: resolved (fixed in 1.24.1-1) bullseye: resolved (fixed in 1.24.1-1) forky: resolved (fixed in 1.24
debian
CVE-2019-7345P4LOWCVSS 4.8fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7345 [MEDIUM] CVE-2019-7345: zoneminder - Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as... Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or JavaScript code. This relates to functions.php. Scope: local bookworm: resolved (fixed in 1.34.6-1) bullseye: reso
debian
CVE-2019-7337P4LOWCVSS 4.8fixed in zoneminder 1.34.6-1 (bookworm)2019
CVE-2019-7337 [MEDIUM] CVE-2019-7337: zoneminder - Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the ... Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any
debian
CVE-2008-3881P4LOWCVSS 4.3fixed in zoneminder 1.24.1-1 (bookworm)2008
CVE-2008-3881 [MEDIUM] CVE-2008-3881: zoneminder - Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and ear... Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files. Scope: local bookworm: resolved (fixed in 1.24.1-1) bullseye: resolved (fixed in 1.24.1-1) forky: resolved (fixed in 1.24.1-1) sid: resolved (fixed in 1.24.1-1) trixie: resol
debian
CVE-2008-6756P4LOWCVSS 2.1fixed in zoneminder 1.22.3-5 (bookworm)2008
CVE-2008-6756 [LOW] CVE-2008-6756: zoneminder - ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which ... ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file. Scope: local bookworm: resolved (fixed in 1.22.3-5) bullseye: resolved (fixed in 1.22.3-5) forky: resolved (fixed in 1.22.3-5) sid: resolved (fixed in 1.22.3-5) trixie: resolved (fixed in 1.22.3-5)
debian
Debian Zoneminder vulnerabilities | cvebase