Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-25063 A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of th… Dashboard 1.3.5+ Fix from $1,6002023-01-01 HIGH 7.8 CVE-2019-14257 pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka Z… Zenoss No fix yet Fix from $1,9502019-08-21 HIGH 7.5 CVE-2019-14258 The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988. Zenoss No fix yet Fix from $1,9502019-08-21 MEDIUM 6.8 CVE-2014-9386 Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by … Zenoss Core after 4.2.5 Fix from $1,6002014-12-15 MEDIUM 6.8 CVE-2014-9385 Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary use… Zenoss Core Mitigation only Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-9251 Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext value… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-9250 Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 HIGH 7.5 CVE-2014-9249 The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po… Zenoss Core after 4.2.5 Fix from $1,9502014-12-15 MEDIUM 5.0 CVE-2014-9248 Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-9245 Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 HIGH 9.3 CVE-2014-6261EPSS 20% Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1… Zenoss Core after 5.0.0 Fix from $1,9502014-12-15 MEDIUM 6.8 CVE-2014-6260 Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary c… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-6259 Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-6258 An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering an arbit… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-6257 Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 HIGH 7.5 CVE-2014-6256 Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2… Zenoss Core after 5.0.0 Fix from $1,9502014-12-15 MEDIUM 6.4 CVE-2014-6255 Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and … Zenoss Core after 4.2.5 Fix from $1,6002014-12-15 MEDIUM 6.8 CVE-2014-6253 Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arb… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.8 CVE-2014-3739 Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web… Zenoss No fix yet Fix from $1,6002014-05-20 MEDIUM 6.8 CVE-2010-0713 Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authe… Zenoss after 2.4.5 Fix from $1,6002010-02-26 MEDIUM 6.5 CVE-2010-0712 Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticat… Zenoss after 2.4.5 Fix from $1,6002010-02-26