CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76553 | CVE-2014-9252 | Candidate | Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416. | Assigned (20141203) | None (candidate not yet proposed) | View | |
76552 | CVE-2014-9251 | Candidate | Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on hash values in the database, aka ZEN-15413. | Assigned (20141203) | None (candidate not yet proposed) | View | |
18290 | CVE-2006-2186 | Candidate | zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the path in an error message. | Assigned (20060504) | None (candidate not yet proposed) | View | |
52446 | CVE-2011-4534 | Candidate | ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of connections and disconnections on TCP port 1101, aka Reference Number 25212. | Assigned (20111122) | None (candidate not yet proposed) | View | |
6540 | CVE-2002-2158 | Candidate | zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 20917 of 20943, showing 5 records out of 104715 total, starting on record 104581, ending on 104585