CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76548 | CVE-2014-9247 | Candidate | Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389. | Assigned (20141203) | None (candidate not yet proposed) | View | |
76546 | CVE-2014-9245 | Candidate | Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382. | Assigned (20141203) | None (candidate not yet proposed) | View | |
73556 | CVE-2014-6257 | Candidate | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper method, aka ZEN-15407. | Assigned (20140905) | None (candidate not yet proposed) | View | |
73555 | CVE-2014-6256 | Candidate | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2) execute access via a move action, aka ZEN-15386. | Assigned (20140905) | None (candidate not yet proposed) | View | |
76687 | CVE-2014-9386 | Candidate | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691. | Assigned (20141212) | None (candidate not yet proposed) | View |
Page 29 of 20943, showing 5 records out of 104715 total, starting on record 141, ending on 145