CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76548  CVE-2014-9247  Candidate  Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389.  Assigned (20141203)  None (candidate not yet proposed)    View
76546  CVE-2014-9245  Candidate  Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382.  Assigned (20141203)  None (candidate not yet proposed)    View
73556  CVE-2014-6257  Candidate  Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper method, aka ZEN-15407.  Assigned (20140905)  None (candidate not yet proposed)    View
73555  CVE-2014-6256  Candidate  Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2) execute access via a move action, aka ZEN-15386.  Assigned (20140905)  None (candidate not yet proposed)    View
76687  CVE-2014-9386  Candidate  Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.  Assigned (20141212)  None (candidate not yet proposed)    View

Page 29 of 20943, showing 5 records out of 104715 total, starting on record 141, ending on 145

Actions