NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
44960 | CVE-2012-3363 | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack. | 2 | 6.4 | Medium | 2017-01-19 | 2013-12-05 | View | |
36094 | CVE-2014-9386 | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691. | 2 | 6.8 | Medium | 2017-01-19 | 2016-03-21 | View | |
33802 | CVE-2014-6256 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2) execute access via a move action, aka ZEN-15386. | 2 | 7.5 | High | 2017-01-19 | 2016-03-21 | View | |
33803 | CVE-2014-6257 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper method, aka ZEN-15407. | 2 | 5 | Medium | 2017-01-19 | 2016-03-21 | View | |
35987 | CVE-2014-9245 | Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382. | 2 | 5 | Medium | 2017-01-19 | 2016-03-21 | View |
Page 17643 of 17672, showing 5 records out of 88360 total, starting on record 88211, ending on 88215