ganglia CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

ganglia vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ganglia-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-52763 A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter. [email protected] 5.4 0.60% 2024-11-19 2026-06-17
CVE-2024-52762 A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter. [email protected] 5.4 0.75% 2024-11-19 2026-06-17
CVE-2019-20379 ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter. [email protected] 6.1 0.79% 2020-01-10 2026-06-16
CVE-2019-20378 ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter. [email protected] 6.1 1.01% 2020-01-10 2026-06-16
CVE-2015-6816 ganglia-web before 3.7.1 allows remote attackers to bypass authentication. [email protected] 9.8 3.56% 2017-08-09 2026-06-16
CVE-2013-1770 Cross-site scripting (XSS) vulnerability in views_view.php in Ganglia Web 3.5.7 allows remote attackers to inject arbitrary web script or HTML via the view_name parameter. [email protected] 4.3 2.16% 2014-04-02 2026-06-16
CVE-2013-6395 Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php. [email protected] 4.3 2.20% 2013-12-05 2026-06-16
CVE-2013-0275 Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web before 3.5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. [email protected] 4.3 1.93% 2013-03-13 2026-06-16
CVE-2012-3448 Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors. [email protected] 7.5 9.94% 2012-08-06 2026-06-16
CVE-2011-3741 Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files. [email protected] 5.0 1.37% 2011-09-23 2026-06-16
CVE-2009-0241 Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname. [email protected] 7.5 5.35% 2009-01-21 2026-06-16
CVE-2007-6465 Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia before 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G, (4) me, (5) x, (6) n, (7) v, (8) l, (9) vl, and (10) st parameters to (b) web/graph.php; and the (11) c, (12) G, (13) h, (14) r, (15) m, (16) s, (17) cr, (18) hc, (19) sh, (20) p, (21) t, (22) jr, (23) js, (24) gw, (25) z, and (26) gs parameters to (c) web/get_context.ph [email protected] 4.3 1.29% 2007-12-19 2026-06-16
CVE-2003-1163 hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index. [email protected] 5.0 1.89% 2003-12-31 2026-06-16
CVE-2002-2104 graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function. [email protected] 7.5 2.06% 2002-12-31 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence