CVE List

Id CVE No. Status Description Phase Votes Comments Actions
31498  CVE-2008-1381  Candidate  ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.  Assigned (20080318)  None (candidate not yet proposed)    View
102188  CVE-2017-5368  Candidate  ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).  Assigned (20170113)  None (candidate not yet proposed)    View
25026  CVE-2007-1669  Candidate  zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.  Assigned (20070324)  None (candidate not yet proposed)    View
9108  CVE-2004-0680  Candidate  Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.  Assigned (20040712)  None (candidate not yet proposed)    View
2778  CVE-2000-1211  Entry  Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.        View

Page 20931 of 20943, showing 5 records out of 104715 total, starting on record 104651, ending on 104655

Actions