Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dashboard MEDIUM 6.1
CVE-2018-25063

A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of th…

Fix: 1.3.5+
Fix from $1,600 2023-01-01
Zenoss HIGH 7.8
CVE-2019-14257

pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka Z…

No fix yet
Fix from $1,950 2019-08-21
Zenoss HIGH 7.5
CVE-2019-14258

The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

No fix yet
Fix from $1,950 2019-08-21
Zenoss Core MEDIUM 6.8
CVE-2014-9386

Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by …

Fix: after 4.2.5
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 6.8
CVE-2014-9385

Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary use…

Mitigation only
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-9251

Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext value…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-9250

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core HIGH 7.5
CVE-2014-9249

The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po…

Fix: after 4.2.5
Fix from $1,950 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-9248

Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-9245

Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core HIGH 9.3
CVE-2014-6261EPSS 20%

Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1…

Fix: after 5.0.0
Fix from $1,950 2014-12-15
Zenoss Core MEDIUM 6.8
CVE-2014-6260

Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary c…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-6259

Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-6258

An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering an arbit…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-6257

Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core HIGH 7.5
CVE-2014-6256

Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2…

Fix: after 5.0.0
Fix from $1,950 2014-12-15
Zenoss Core MEDIUM 6.4
CVE-2014-6255

Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and …

Fix: after 4.2.5
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 6.8
CVE-2014-6253

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arb…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss MEDIUM 5.8
CVE-2014-3739

Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web…

No fix yet
Fix from $1,600 2014-05-20
Zenoss MEDIUM 6.8
CVE-2010-0713

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authe…

Fix: after 2.4.5
Fix from $1,600 2010-02-26
Zenoss MEDIUM 6.5
CVE-2010-0712

Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticat…

Fix: after 2.4.5
Fix from $1,600 2010-02-26