AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-7108

MEDIUM · CVSS 5.5 EPSS 59.55%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-01-15 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.5. Its EPSS score suggests a 59.5% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2013-7108
Severity
MEDIUM
CVSS
5.5
EPSS
59.55%

Original NVD Description

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.