5
CVSSv2

CVE-2009-4501

Published: 31/12/2009 Updated: 01/01/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server prior to 1.6.8 allows remote malicious users to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL pointer dereference, as demonstrated using the Command keyword.

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 1.1.3

zabbix zabbix 1.4.6

zabbix zabbix 1.4.4

zabbix zabbix 1.6.6

zabbix zabbix 1.4.3

zabbix zabbix 1.4.2

zabbix zabbix 1.1.5

zabbix zabbix

zabbix zabbix 1.1.4

zabbix zabbix 1.1.2

Exploits

Zabbix Server : Multiple remote vulnerabilities From: Nicob <nicob () nicob net> Date: Sun, 13 Dec 2009 16:28:35 +0100 From Wikipedia : "Zabbix is a network management system application [] designed to monitor and track the status of various network services, servers, and other network hardware" [Zabbix Server : Remote command executio ...