Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2012-5503 ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors. Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5505 atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name. Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5506 python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed re… Plone after 4.2.2 Fix from $1,6002014-09-30 HIGH 8.5 CVE-2012-5487 The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privile… Plone after 4.2.2 Fix from $1,9502014-09-30 MEDIUM 6.8 CVE-2012-5485 registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to t… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 6.4 CVE-2012-5486 ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP he… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5488 python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObje… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.5 CVE-2013-7061 Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via … Plone Mitigation only Fix from $1,6002014-05-02 MEDIUM 5.0 CVE-2013-7060 Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj… Plone Mitigation only Fix from $1,6002014-05-02 MEDIUM 6.5 CVE-2013-4189 Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.8 CVE-2013-4191 zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.8 CVE-2013-4195 Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.5 CVE-2013-4197 member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portr… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.0 CVE-2013-4196 The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restric… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.8 CVE-2013-4200 The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs star… Plone Patch available Fix from $1,6002014-01-21 MEDIUM 5.0 CVE-2011-4462 Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows… Plone after 4.1.3 Fix from $1,6002011-12-30 HIGH 9.3 CVE-2011-3587EPSS 78% Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to exe… Plone Patch available Fix from $1,9502011-10-10 HIGH 9.3 CVE-2011-4030 The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publish… Cmfeditions Patch available Fix from $1,9502011-10-10 HIGH 7.5 CVE-2011-2528 Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix201… Plone Hotfix 20110720 Patch available Fix from $1,9502011-07-19 MEDIUM 5.5 CVE-2011-1950 plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exp… Plone Patch available Fix from $1,6002011-06-06 MEDIUM 6.0 CVE-2009-0662 The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authent… Plonepas Patch available Fix from $1,6002009-04-23 HIGH 10.0 CVE-2008-1393 Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account,… Plone Cms after 3.0.5 Fix from $1,9502008-03-20 HIGH 7.5 CVE-2008-1394 Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remo… Plone Cms after 2.5.1 Fix from $1,9502008-03-20 HIGH 7.5 CVE-2008-1395 Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex… Plone Cms Mitigation only Fix from $1,9502008-03-20 HIGH 7.5 CVE-2007-5741 Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects fo… Plone Patch available Fix from $1,9502007-11-07 MEDIUM 6.4 CVE-2006-4247 Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of… Plone Patch available Fix from $1,6002006-09-29 MEDIUM 5.0 CVE-2006-1711 Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword m… Plone Mitigation only Fix from $1,6002006-04-11