İçeriğe atla
Noroxi

zope kayıtları

zope üreticisine ait 52 yayımlanmış kayıt.

Tüm kayıtlar

52 kayıt
  • CVE-2011-3587
    60Bu hafta

    Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke

    KritikCVSS 9,3SilahlaştırılmışEPSS %78

    plone · plone10 Eki 2011

  • CVE-2000-0062
    41Planlayın

    The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

    KritikCVSS 10,0İstismar yokEPSS %2

    zope · zope4 Oca 2000

  • CVE-2024-24811
    39İzleyin

    Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution

    KritikCVSS 9,8İstismar yokEPSS %1

    zope · sqlalchemyda7 Şub 2024

  • CVE-2023-37271
    39İzleyin

    RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

    KritikCVSS 9,9İstismar yokEPSS %1

    zope · restrictedpython11 Tem 2023

  • CVE-2015-7293
    36İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    plone · plone25 Eyl 2017

  • CVE-2021-32633
    36İzleyin

    Remote Code Execution via traversal in TAL expressions

    YüksekCVSS 8,8İstismar yokEPSS %2

    zope · zope21 May 2021

  • CVE-2021-32674
    35İzleyin

    Remote Code Execution via traversal in TAL expressions

    YüksekCVSS 8,8İstismar yokEPSS %2

    zope · zope8 Haz 2021

  • CVE-2024-47532
    34İzleyin

    RestrictedPython information leakage via `AttributeError.obj` and the `string` module

    YüksekCVSS 8,7İstismar yokEPSS %1

    zope · restrictedpython30 Eyl 2024

  • CVE-2024-51734
    34İzleyin

    User data deletion by anoynmous users in Zope

    YüksekCVSS 8,7İstismar yokEPSS %0

    zopefoundation · accesscontrol4 Kas 2024

  • CVE-2005-3323
    31İzleyin

    docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in Re

    YüksekCVSS 7,5İstismar yokEPSS %3

    zope · zope27 Eki 2005

  • CVE-2000-0483
    31İzleyin

    The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

    YüksekCVSS 7,5İstismar yokEPSS %3

    zope · zope15 Haz 2000

  • CVE-2009-0669
    31İzleyin

    Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to

    YüksekCVSS 7,5İstismar yokEPSS %3

    zope · zodb7 Ağu 2009

  • CVE-2011-2528
    31İzleyin

    Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone

    YüksekCVSS 7,5İstismar yokEPSS %2

    plone · plone hotfix 2011072019 Tem 2011

  • CVE-2021-36089
    31İzleyin

    Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecomp

    YüksekCVSS 7,8İstismar yokEPSS %1

    zope · grok30 Haz 2021

  • CVE-2002-0170
    30İzleyin

    Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents

    YüksekCVSS 7,5İstismar yokEPSS %2

    zope · zope22 Nis 2002

  • CVE-2002-0688
    30İzleyin

    ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictio

    YüksekCVSS 7,5İstismar yokEPSS %1

    zope · zope23 Tem 2002

  • CVE-2000-1211
    30İzleyin

    Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects

    YüksekCVSS 7,5İstismar yokEPSS %1

    zope · zope16 Ara 2000

  • CVE-2001-1227
    30İzleyin

    Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt at

    YüksekCVSS 7,5İstismar yokEPSS %1

    zope · zope10 Eki 2001

  • CVE-2001-1278
    30İzleyin

    Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt at

    YüksekCVSS 7,5İstismar yokEPSS %1

    zope · zope10 Eki 2001

  • CVE-2023-36814
    30İzleyin

    zopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

    YüksekCVSS 7,5İstismar yokEPSS %1

    zope · products.cmfcore3 Tem 2023

  • CVE-2023-41039
    30İzleyin

    Sandbox escape via various forms of "format" in RestrictedPython

    YüksekCVSS 7,7İstismar yokEPSS %1

    zope · restrictedpython30 Ağu 2023

  • CVE-2023-41050
    30İzleyin

    Information disclosure through Python's "format" functionality in Zope AccessControl

    YüksekCVSS 7,7İstismar yokEPSS %1

    zope · accesscontrol6 Eyl 2023

  • CVE-2021-32811
    29İzleyin

    Remote Code Execution via Script (Python) objects under Python 3

    YüksekCVSS 7,2İstismar yokEPSS %2

    zope · accesscontrol2 Ağu 2021

  • CVE-2021-32807
    29İzleyin

    Remote Code Execution via unsafe classes in otherwise permitted modules

    YüksekCVSS 7,2İstismar yokEPSS %2

    zope · accesscontrol30 Tem 2021

  • CVE-2000-0725
    28İzleyin

    Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by m

    YüksekCVSS 7,2İstismar yokEPSS %0

    zope · zope20 Eki 2000