zabbix vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the zabbix package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2024-42328

<1:7.0.5+dfsg-1
  • L
CVE-2024-42332

<1:7.0.5+dfsg-1
  • L
CVE-2024-36468

<1:7.0.3+dfsg-1
  • L
CVE-2024-36464

<1:7.0.9+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.24+dfsg-1
  • L
CVE-2024-36466

<1:7.0.1+dfsg-1
  • H
Improper Input Validation

<1:6.0.23+dfsg-1
  • H
Reliance on Cookies without Validation and Integrity Checking

<1:6.0.23+dfsg-1
  • L
Arbitrary Code Injection

<1:6.0.23+dfsg-1
  • C
SQL Injection

<1:3.0.4+dfsg-1
  • M
Improper Authentication

<1:2.0.4+dfsg-2
  • H
CVE-2017-2825

<1:3.0.7+dfsg-3
  • H
SQL Injection

<1:2.0.2+dfsg-1
  • M
Improper Authentication

<1:2.2.2+dfsg-1
  • L
CVE-2024-42333

<1:7.0.5+dfsg-1
  • H
SQL Injection

<1:1.8.9-1
  • L
CVE-2024-42326

<1:7.0.5+dfsg-1
  • M
Information Exposure

<1:5.0.7+dfsg-1
  • L
Access Restriction Bypass

<1:2.2.2+dfsg-1
  • L
Open Redirect

<1:3.0.17+dfsg-1
  • L
CVE-2008-1353

<1:1.4.5-1
  • L
CVE-2024-36465

<1:7.0.9+dfsg-1
  • H
SQL Injection

<1:1.8.2-1
  • M
Out-of-Bounds

<1:1.8-1
  • C
CVE-2007-0640

<1:1.1.4-8
  • C
Arbitrary Code Injection

<1:6.0.24+dfsg-1
  • L
CVE-2024-42327

<1:7.0.1+dfsg-1
  • H
Incorrect Permission Assignment for Critical Resource

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • M
Improper Input Validation

<1:6.0.13+dfsg-1
  • L
CVE-2024-22117

<1:7.0.5+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • C
CVE-2020-11800

<1:4.0.0+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • H
OS Command Injection

<1:3.0.7+dfsg-3
  • M
Cryptographic Issues

<1:2.0.7+dfsg-1
  • C
Improper Input Validation

<1:2.0.7+dfsg-1
  • H
SQL Injection

<1:1.8.2-1
  • L
Information Exposure

<1:4.0.0+dfsg-1
  • M
Out-of-Bounds

<1:1.8-1
  • M
Resource Management Errors

<1:1.8.6-1
  • L
CVE-2024-36469

<1:7.0.9+dfsg-1
  • H
Insufficiently Protected Credentials

<1:7.0.1+dfsg-1
  • L
CVE-2024-45700

<1:7.0.10+dfsg-1
  • L
CVE-2024-22120

<1:6.0.29+dfsg-1
  • L
CVE-2024-42331

<1:7.0.5+dfsg-1
  • H
Files or Directories Accessible to External Parties

<1:6.0.23+dfsg-1
  • C
Incorrect Authorization

<1:6.0.13+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • C
Authorization Bypass Through User-Controlled Key

<1:5.0.0+dfsg-1
  • L
CVE-2024-45699

<1:7.0.9+dfsg-1
  • H
SQL Injection

<1:3.0.3+dfsg-1
  • H
Allocation of Resources Without Limits or Throttling

<1:7.0.1+dfsg-1
  • L
Arbitrary Code Injection

<1:7.0.0+dfsg-1
  • H
Arbitrary Code Injection

<1:7.0.0+dfsg-1
  • L
CVE-2024-42329

<1:7.0.5+dfsg-1
  • M
OS Command Injection

<1:1.8-1
  • H
Improper Validation of Array Index

<1:6.0.23+dfsg-1
  • M
CVE-2006-6693

<1:1.1.2-4
  • C
Incorrect Permission Assignment for Critical Resource

<1:5.0.0+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • L
Information Exposure

<1:1.8.6-1
  • M
Allocation of Resources Without Limits or Throttling

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • M
Improper Authentication

<1:6.0.7+dfsg-2
  • H
Cross-site Request Forgery (CSRF)

<1:5.0.8+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:1.8.3-1
  • H
SQL Injection

<1:1.8-1
  • L
Arbitrary Code Injection

<1:2.2.0+dfsg-6
  • M
Cross-site Scripting (XSS)

<1:1.8.6-1
  • H
Out-of-bounds Write

<1:6.0.23+dfsg-1
  • M
CVE-2014-1685

<1:2.2.2+dfsg-1
  • L
CVE-2024-42330

<1:7.0.5+dfsg-1
  • H
CVE-2024-36461

<1:7.0.1+dfsg-1
  • L
CVE-2024-36463

<1:7.0.3+dfsg-1
  • M
Improper Preservation of Permissions

<1:7.0.0+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • C
Arbitrary Command Injection

<1:7.0.0+dfsg-1
  • H
Incorrect Permission Assignment for Critical Resource

<1:6.0.7+dfsg-2
  • M
Cross-site Scripting (XSS)

<1:5.0.2+dfsg-1
  • H
Inadequate Encryption Strength

<1:5.0.0+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:1.8.10-1
  • M
Information Exposure

<1:1.8.9-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • H
SQL Injection

<1:2.2.7+dfsg-2
  • M
CVE-2006-6692

<1:1.1.2-4
  • L
CVE-2024-36467

<1:7.0.2+dfsg-1
  • H
Improper Check for Unusual or Exceptional Conditions

<1:6.0.24+dfsg-1
  • H
Out-of-bounds Write

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.23+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • L
CVE-2024-42325

<1:7.0.9+dfsg-1
  • M
Cross-site Scripting (XSS)

<1:6.0.7+dfsg-2
  • C
XML External Entity (XXE) Injection

<1:2.2.5+dfsg-1
  • H
Access Restriction Bypass

<1:1.8-1
  • M
Cross-site Scripting (XSS)

<1:1.8.10-1
  • M
Configuration

<1:1.4.2-4
  • C
SQL Injection

<1:2.0.8+dfsg-2