FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-28 15:43:32 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
1cecd5e0-c372-11e5-96d6-14dae9d210b8xymon-server -- multiple vulnerabilities

J.C. Cleaver reports:

  • CVE-2016-2054: Buffer overflow in xymond handling of "config" command

  • CVE-2016-2055: Access to possibly confidential files in the Xymon configuration directory

  • CVE-2016-2056: Shell command injection in the "useradm" and "chpasswd" web applications

  • CVE-2016-2057: Incorrect permissions on IPC queues used by the xymond daemon can bypass IP access filtering

  • CVE-2016-2058: Javascript injection in "detailed status webpage" of monitoring items; XSS vulnerability via malformed acknowledgment messages


Discovery 2016-01-19
Entry 2016-02-09
xymon-server
< 4.3.25

http://lists.xymon.com/pipermail/xymon/2016-February/042986.html
CVE-2016-2054
CVE-2016-2055
CVE-2016-2056
CVE-2016-2057
CVE-2016-2058