Zenoss kayıtları
zenoss üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %7,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-399 Resource Management Errors2
- CWE-255 Credentials Management Errors2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2014-6261İstismar yok | Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary czenoss · zenoss core · CWE-94 | Kritik9,3 | — | %19,7 | 15 Ara 2014 |
32İzleyin | CVE-2014-6262İstismar yok | Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remotezenoss · zenoss core · CWE-134 | Yüksek7,5 | — | %7,2 | 11 Şub 2020 |
31İzleyin | CVE-2019-14258İstismar yok | The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.zenoss · zenoss · CWE-611 | Yüksek7,5 | — | %1,7 | 21 Ağu 2019 |
31İzleyin | CVE-2019-14257İstismar yok | pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are droppzenoss · zenoss · CWE-264 | Yüksek7,8 | — | %0,6 | 21 Ağu 2019 |
30İzleyin | CVE-2014-9249İstismar yok | The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecifiezenoss · zenoss core · CWE-264 | Yüksek7,5 | — | %1,6 | 15 Ara 2014 |
30İzleyin | CVE-2014-6256İstismar yok | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) rzenoss · zenoss core · CWE-264 | Yüksek7,5 | — | %1,5 | 15 Ara 2014 |
28İzleyin | CVE-2014-9386İstismar yok | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack seszenoss · zenoss core | Orta6,8 | — | %2,0 | 15 Ara 2014 |
28İzleyin | CVE-2010-0713Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack zenoss · zenoss · CWE-352 | Orta6,8 | — | %1,9 | 26 Şub 2010 |
28İzleyin | CVE-2014-6260İstismar yok | Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arzenoss · zenoss core · CWE-77 | Orta6,8 | — | %1,8 | 15 Ara 2014 |
27İzleyin | CVE-2010-0712Kavram kanıtı | Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote auzenoss · zenoss · CWE-89 | Orta6,5 | — | %2,0 | 26 Şub 2010 |
27İzleyin | CVE-2014-9385İstismar yok | Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbizenoss · zenoss core · CWE-352 | Orta6,8 | — | %1,2 | 15 Ara 2014 |
27İzleyin | CVE-2014-6253İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authenticatizenoss · zenoss core · CWE-352 | Orta6,8 | — | %0,7 | 15 Ara 2014 |
26İzleyin | CVE-2014-6255İstismar yok | Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web szenoss · zenoss core | Orta6,4 | — | %2,1 | 15 Ara 2014 |
24İzleyin | CVE-2018-25063İstismar yok | Zenoss Dashboard defaultportlets.js cross site scriptingzenoss · dashboard · CWE-79 | Orta6,1 | — | %0,5 | 1 Oca 2023 |
23İzleyin | CVE-2014-3739İstismar yok | Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbizenoss · zenoss · CWE-20 | Orta5,8 | — | %1,3 | 20 May 2014 |
20İzleyin | CVE-2014-6259İstismar yok | Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of zenoss · zenoss core · CWE-399 | Orta5,0 | — | %1,6 | 15 Ara 2014 |
20İzleyin | CVE-2014-9250İstismar yok | Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier zenoss · zenoss core · CWE-200 | Orta5,0 | — | %1,5 | 15 Ara 2014 |
20İzleyin | CVE-2014-6258İstismar yok | An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggeringzenoss · zenoss core · CWE-399 | Orta5,0 | — | %1,5 | 15 Ara 2014 |
20İzleyin | CVE-2014-6257İstismar yok | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object zenoss · zenoss core · CWE-264 | Orta5,0 | — | %1,4 | 15 Ara 2014 |
20İzleyin | CVE-2014-9245İstismar yok | Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid nzenoss · zenoss core · CWE-200 | Orta5,0 | — | %1,4 | 15 Ara 2014 |
20İzleyin | CVE-2014-9251İstismar yok | Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartzenoss · zenoss core · CWE-255 | Orta5,0 | — | %1,3 | 15 Ara 2014 |
20İzleyin | CVE-2014-9248İstismar yok | Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-forzenoss · zenoss core · CWE-255 | Orta5,0 | — | %1,2 | 15 Ara 2014 |
18İzleyin | CVE-2014-3738Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a dzenoss · zenoss · CWE-79 | Orta4,3 | — | %3,7 | 20 May 2014 |
17İzleyin | CVE-2014-6254İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script orzenoss · zenoss core · CWE-79 | Orta4,3 | — | %1,2 | 15 Ara 2014 |
16İzleyin | CVE-2014-9247İstismar yok | Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role informzenoss · zenoss core · CWE-200 | Orta4,0 | — | %1,1 | 15 Ara 2014 |
- CVE-2014-626143Planlayın
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary c
KritikCVSS 9,3İstismar yokEPSS %20zenoss · zenoss core15 Ara 2014
- CVE-2014-626232İzleyin
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote
YüksekCVSS 7,5İstismar yokEPSS %7zenoss · zenoss core11 Şub 2020
- CVE-2019-1425831İzleyin
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
YüksekCVSS 7,5İstismar yokEPSS %2zenoss · zenoss21 Ağu 2019
- CVE-2019-1425731İzleyin
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropp
YüksekCVSS 7,8İstismar yokEPSS %1zenoss · zenoss21 Ağu 2019
- CVE-2014-924930İzleyin
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecifie
YüksekCVSS 7,5İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2014-625630İzleyin
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) r
YüksekCVSS 7,5İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2014-938628İzleyin
Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack ses
OrtaCVSS 6,8İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2010-071328İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack
OrtaCVSS 6,8Kavram kanıtıEPSS %2zenoss · zenoss26 Şub 2010
- CVE-2014-626028İzleyin
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute ar
OrtaCVSS 6,8İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2010-071227İzleyin
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote au
OrtaCVSS 6,5Kavram kanıtıEPSS %2zenoss · zenoss26 Şub 2010
- CVE-2014-938527İzleyin
Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbi
OrtaCVSS 6,8İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-625327İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authenticati
OrtaCVSS 6,8İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-625526İzleyin
Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web s
OrtaCVSS 6,4İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2018-2506324İzleyin
Zenoss Dashboard defaultportlets.js cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1zenoss · dashboard1 Oca 2023
- CVE-2014-373923İzleyin
Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbi
OrtaCVSS 5,8İstismar yokEPSS %1zenoss · zenoss20 May 2014
- CVE-2014-625920İzleyin
Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of
OrtaCVSS 5,0İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2014-925020İzleyin
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier
OrtaCVSS 5,0İstismar yokEPSS %2zenoss · zenoss core15 Ara 2014
- CVE-2014-625820İzleyin
An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering
OrtaCVSS 5,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-625720İzleyin
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object
OrtaCVSS 5,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-924520İzleyin
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid n
OrtaCVSS 5,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-925120İzleyin
Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleart
OrtaCVSS 5,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-924820İzleyin
Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-for
OrtaCVSS 5,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-373818İzleyin
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a d
OrtaCVSS 4,3Kavram kanıtıEPSS %4zenoss · zenoss20 May 2014
- CVE-2014-625417İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014
- CVE-2014-924716İzleyin
Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role inform
OrtaCVSS 4,0İstismar yokEPSS %1zenoss · zenoss core15 Ara 2014