NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78662 | CVE-2001-1227 | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
78713 | CVE-2001-1278 | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
76966 | CVE-2000-0725 | Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. | 2 | 7.2 | High | 2017-01-05 | 2008-09-10 | View | |
47332 | CVE-2012-6661 | Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2). | 2 | 5 | Medium | 2017-01-19 | 2014-11-04 | View | |
62132 | CVE-2006-3458 | Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files. | 2 | 2.1 | Low | 2016-12-20 | 2011-03-10 | View |
Page 12 of 17672, showing 5 records out of 88360 total, starting on record 56, ending on 60