Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 7.0.2  Security Vulnerabilities
When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.
CVSS Score
3.3
EPSS Score
0.002
Published
2024-11-27
The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various reasons without an error description and then the wd->error will be NULL and trying to read from it will result in a crash.
CVSS Score
3.3
EPSS Score
0.002
Published
2024-11-27
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.
CVSS Score
2.2
EPSS Score
0.005
Published
2024-11-26
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
CVSS Score
6.5
EPSS Score
0.008
Published
2024-11-26


Contact Us

Shodan ® - All rights reserved