ALT-PU-2019-2687-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-13273
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
Modified: 2024-11-21
CVE-2019-13274
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
Modified: 2024-11-21
CVE-2019-13451
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13452
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/reportlog.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/reportlog.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13455
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/acknowledge.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/acknowledge.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13473
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- https://www.vulnerability-lab.com/get_content.php?id=2183
- https://www.vulnerability-lab.com/get_content.php?id=2183
Modified: 2024-11-21
CVE-2019-13474
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2019/Sep/12
- http://seclists.org/fulldisclosure/2019/Sep/12
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- 20230904 Vulnerabilities in Internet Radio auna IR-160 SE (UIProto)
- https://www.vulnerability-lab.com/get_content.php?id=2183
- https://www.vulnerability-lab.com/get_content.php?id=2183
Modified: 2024-11-21
CVE-2019-13484
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/appfeed.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/appfeed.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13485
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/history.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html
Modified: 2024-11-21
CVE-2019-13486
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/svcstatus.c
- https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/svcstatus.c
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html
- https://lists.xymon.com/archive/2019-July/046570.html
- https://lists.xymon.com/archive/2019-July/046570.html