cbcvebase.

Smokeping vulnerabilities

6 known vulnerabilities affecting smokeping/smokeping.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2016-20015P3HIGHCVSS 7.5≤ 2.7.3-r12022-09-20
CVE-2016-20015 [HIGH] CWE-362 CVE-2016-20015: In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.
nvd
CVE-2015-0859P3HIGHCVSS 7.5≥ 0, < 2.6.11-22015-12-03
CVE-2015-0859 [HIGH] CVE-2015-0859: The Debian build procedure for the smokeping package in wheezy before 2 The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.
osv
CVE-2017-20147P4MEDIUMCVSS 6.5≤ 2.7.3-r12022-09-20
CVE-2017-20147 [MEDIUM] CWE-377 CVE-2017-20147: In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to arbitrary PIDs when the service is stopped.
nvd
CVE-2013-4158P4MEDIUMCVSS 6.1fixed in 2.6.92019-12-11
CVE-2013-4158 [MEDIUM] CVE-2013-4158: smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
nvd
CVE-2013-4168P4MEDIUMCVSS 6.1v2.6.92019-11-01
CVE-2013-4168 [MEDIUM] CWE-79 CVE-2013-4168: Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
nvdosv
CVE-2012-0790P4MEDIUMCVSS 4.3fixed in 2.6.92012-01-24
CVE-2012-0790 [MEDIUM] CWE-79 CVE-2012-0790: Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versi Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.
nvdosv
Smokeping vulnerabilities | cvebase