The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a symlink attack on /tmp/ipxping/ipxping.
📦
plugins
Vendor: nagios
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
8
Total Indexed
Avg. EPSS
3.71%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
4.4
CVSS
Severity: MEDIUM
5.0
CVSS
Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via crafted snmpget replies.
Severity: MEDIUM
6.8
CVSS
CVE-2007-5198
Exploit Found
Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading "L" characters.
Severity: MEDIUM