İçeriğe atla
Noroxi

Zenoss kayıtları

zenoss üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%7,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2014-6261
    43Planlayın

    Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary c

    KritikCVSS 9,3İstismar yokEPSS %20

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6262
    32İzleyin

    Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote

    YüksekCVSS 7,5İstismar yokEPSS %7

    zenoss · zenoss core11 Şub 2020

  • CVE-2019-14258
    31İzleyin

    The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

    YüksekCVSS 7,5İstismar yokEPSS %2

    zenoss · zenoss21 Ağu 2019

  • CVE-2019-14257
    31İzleyin

    pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropp

    YüksekCVSS 7,8İstismar yokEPSS %1

    zenoss · zenoss21 Ağu 2019

  • CVE-2014-9249
    30İzleyin

    The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecifie

    YüksekCVSS 7,5İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6256
    30İzleyin

    Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) r

    YüksekCVSS 7,5İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9386
    28İzleyin

    Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack ses

    OrtaCVSS 6,8İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2010-0713
    28İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    zenoss · zenoss26 Şub 2010

  • CVE-2014-6260
    28İzleyin

    Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute ar

    OrtaCVSS 6,8İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2010-0712
    27İzleyin

    Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote au

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    zenoss · zenoss26 Şub 2010

  • CVE-2014-9385
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbi

    OrtaCVSS 6,8İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6253
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authenticati

    OrtaCVSS 6,8İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6255
    26İzleyin

    Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web s

    OrtaCVSS 6,4İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2018-25063
    24İzleyin

    Zenoss Dashboard defaultportlets.js cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    zenoss · dashboard1 Oca 2023

  • CVE-2014-3739
    23İzleyin

    Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbi

    OrtaCVSS 5,8İstismar yokEPSS %1

    zenoss · zenoss20 May 2014

  • CVE-2014-6259
    20İzleyin

    Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of

    OrtaCVSS 5,0İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9250
    20İzleyin

    Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier

    OrtaCVSS 5,0İstismar yokEPSS %2

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6258
    20İzleyin

    An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering

    OrtaCVSS 5,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-6257
    20İzleyin

    Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object

    OrtaCVSS 5,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9245
    20İzleyin

    Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid n

    OrtaCVSS 5,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9251
    20İzleyin

    Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleart

    OrtaCVSS 5,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9248
    20İzleyin

    Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-for

    OrtaCVSS 5,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-3738
    18İzleyin

    Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a d

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    zenoss · zenoss20 May 2014

  • CVE-2014-6254
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or

    OrtaCVSS 4,3İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014

  • CVE-2014-9247
    16İzleyin

    Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role inform

    OrtaCVSS 4,0İstismar yokEPSS %1

    zenoss · zenoss core15 Ara 2014