zope kayıtları
zope üreticisine ait 52 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,9
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %78,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes2
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
52 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2011-3587Silahlaştırılmış | Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackeplone · plone | Kritik9,3 | — | %78,1 | 10 Eki 2011 |
41Planlayın | CVE-2000-0062İstismar yok | The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.zope · zope | Kritik10,0 | — | %2,2 | 4 Oca 2000 |
39İzleyin | CVE-2024-24811İstismar yok | Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query executionzope · sqlalchemyda · CWE-89 | Kritik9,8 | — | %0,9 | 7 Şub 2024 |
39İzleyin | CVE-2023-37271İstismar yok | RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escapezope · restrictedpython · CWE-913 | Kritik9,9 | — | %0,8 | 11 Tem 2023 |
36İzleyin | CVE-2015-7293Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.plone · plone · CWE-352 | Yüksek8,8 | — | %3,0 | 25 Eyl 2017 |
36İzleyin | CVE-2021-32633İstismar yok | Remote Code Execution via traversal in TAL expressionszope · zope · CWE-22 | Yüksek8,8 | — | %1,9 | 21 May 2021 |
35İzleyin | CVE-2021-32674İstismar yok | Remote Code Execution via traversal in TAL expressionszope · zope · CWE-22 | Yüksek8,8 | — | %1,6 | 8 Haz 2021 |
34İzleyin | CVE-2024-47532İstismar yok | RestrictedPython information leakage via `AttributeError.obj` and the `string` modulezope · restrictedpython · CWE-200 | Yüksek8,7 | — | %0,7 | 30 Eyl 2024 |
34İzleyin | CVE-2024-51734İstismar yok | User data deletion by anoynmous users in Zopezopefoundation · accesscontrol · CWE-284 | Yüksek8,7 | — | %0,4 | 4 Kas 2024 |
31İzleyin | CVE-2005-3323İstismar yok | docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in Rezope · zope | Yüksek7,5 | — | %3,0 | 27 Eki 2005 |
31İzleyin | CVE-2000-0483İstismar yok | The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.zope · zope | Yüksek7,5 | — | %3,0 | 15 Haz 2000 |
31İzleyin | CVE-2009-0669İstismar yok | Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers tozope · zodb · CWE-287 | Yüksek7,5 | — | %2,9 | 7 Ağu 2009 |
31İzleyin | CVE-2011-2528İstismar yok | Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Ploneplone · plone hotfix 20110720 | Yüksek7,5 | — | %2,0 | 19 Tem 2011 |
31İzleyin | CVE-2021-36089İstismar yok | Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompzope · grok · CWE-787 | Yüksek7,8 | — | %1,2 | 30 Haz 2021 |
30İzleyin | CVE-2002-0170İstismar yok | Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents zope · zope | Yüksek7,5 | — | %1,6 | 22 Nis 2002 |
30İzleyin | CVE-2002-0688İstismar yok | ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictiozope · zope | Yüksek7,5 | — | %1,4 | 23 Tem 2002 |
30İzleyin | CVE-2000-1211İstismar yok | Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objectszope · zope | Yüksek7,5 | — | %1,4 | 16 Ara 2000 |
30İzleyin | CVE-2001-1227İstismar yok | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt atzope · zope | Yüksek7,5 | — | %1,4 | 10 Eki 2001 |
30İzleyin | CVE-2001-1278İstismar yok | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt atzope · zope | Yüksek7,5 | — | %1,4 | 10 Eki 2001 |
30İzleyin | CVE-2023-36814İstismar yok | zopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal modulezope · products.cmfcore · CWE-770 | Yüksek7,5 | — | %0,7 | 3 Tem 2023 |
30İzleyin | CVE-2023-41039İstismar yok | Sandbox escape via various forms of "format" in RestrictedPythonzope · restrictedpython · CWE-74 | Yüksek7,7 | — | %0,7 | 30 Ağu 2023 |
30İzleyin | CVE-2023-41050İstismar yok | Information disclosure through Python's "format" functionality in Zope AccessControlzope · accesscontrol · CWE-200 | Yüksek7,7 | — | %0,6 | 6 Eyl 2023 |
29İzleyin | CVE-2021-32811İstismar yok | Remote Code Execution via Script (Python) objects under Python 3zope · accesscontrol · CWE-915 | Yüksek7,2 | — | %2,3 | 2 Ağu 2021 |
29İzleyin | CVE-2021-32807İstismar yok | Remote Code Execution via unsafe classes in otherwise permitted moduleszope · accesscontrol · CWE-915 | Yüksek7,2 | — | %2,0 | 30 Tem 2021 |
28İzleyin | CVE-2000-0725İstismar yok | Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by mzope · zope | Yüksek7,2 | — | %0,5 | 20 Eki 2000 |
- CVE-2011-358760Bu hafta
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke
KritikCVSS 9,3SilahlaştırılmışEPSS %78plone · plone10 Eki 2011
- CVE-2000-006241Planlayın
The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.
KritikCVSS 10,0İstismar yokEPSS %2zope · zope4 Oca 2000
- CVE-2024-2481139İzleyin
Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution
KritikCVSS 9,8İstismar yokEPSS %1zope · sqlalchemyda7 Şub 2024
- CVE-2023-3727139İzleyin
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
KritikCVSS 9,9İstismar yokEPSS %1zope · restrictedpython11 Tem 2023
- CVE-2015-729336İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
YüksekCVSS 8,8Kavram kanıtıEPSS %3plone · plone25 Eyl 2017
- CVE-2021-3263336İzleyin
Remote Code Execution via traversal in TAL expressions
YüksekCVSS 8,8İstismar yokEPSS %2zope · zope21 May 2021
- CVE-2021-3267435İzleyin
Remote Code Execution via traversal in TAL expressions
YüksekCVSS 8,8İstismar yokEPSS %2zope · zope8 Haz 2021
- CVE-2024-4753234İzleyin
RestrictedPython information leakage via `AttributeError.obj` and the `string` module
YüksekCVSS 8,7İstismar yokEPSS %1zope · restrictedpython30 Eyl 2024
- CVE-2024-5173434İzleyin
User data deletion by anoynmous users in Zope
YüksekCVSS 8,7İstismar yokEPSS %0zopefoundation · accesscontrol4 Kas 2024
- CVE-2005-332331İzleyin
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in Re
YüksekCVSS 7,5İstismar yokEPSS %3zope · zope27 Eki 2005
- CVE-2000-048331İzleyin
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
YüksekCVSS 7,5İstismar yokEPSS %3zope · zope15 Haz 2000
- CVE-2009-066931İzleyin
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %3zope · zodb7 Ağu 2009
- CVE-2011-252831İzleyin
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone
YüksekCVSS 7,5İstismar yokEPSS %2plone · plone hotfix 2011072019 Tem 2011
- CVE-2021-3608931İzleyin
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecomp
YüksekCVSS 7,8İstismar yokEPSS %1zope · grok30 Haz 2021
- CVE-2002-017030İzleyin
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents
YüksekCVSS 7,5İstismar yokEPSS %2zope · zope22 Nis 2002
- CVE-2002-068830İzleyin
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictio
YüksekCVSS 7,5İstismar yokEPSS %1zope · zope23 Tem 2002
- CVE-2000-121130İzleyin
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects
YüksekCVSS 7,5İstismar yokEPSS %1zope · zope16 Ara 2000
- CVE-2001-122730İzleyin
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt at
YüksekCVSS 7,5İstismar yokEPSS %1zope · zope10 Eki 2001
- CVE-2001-127830İzleyin
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt at
YüksekCVSS 7,5İstismar yokEPSS %1zope · zope10 Eki 2001
- CVE-2023-3681430İzleyin
zopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
YüksekCVSS 7,5İstismar yokEPSS %1zope · products.cmfcore3 Tem 2023
- CVE-2023-4103930İzleyin
Sandbox escape via various forms of "format" in RestrictedPython
YüksekCVSS 7,7İstismar yokEPSS %1zope · restrictedpython30 Ağu 2023
- CVE-2023-4105030İzleyin
Information disclosure through Python's "format" functionality in Zope AccessControl
YüksekCVSS 7,7İstismar yokEPSS %1zope · accesscontrol6 Eyl 2023
- CVE-2021-3281129İzleyin
Remote Code Execution via Script (Python) objects under Python 3
YüksekCVSS 7,2İstismar yokEPSS %2zope · accesscontrol2 Ağu 2021
- CVE-2021-3280729İzleyin
Remote Code Execution via unsafe classes in otherwise permitted modules
YüksekCVSS 7,2İstismar yokEPSS %2zope · accesscontrol30 Tem 2021
- CVE-2000-072528İzleyin
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by m
YüksekCVSS 7,2İstismar yokEPSS %0zope · zope20 Eki 2000