Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2014-6254

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet name, or (6) a string to a helper method, aka ZEN-15381 and ZEN-15410.
0
Attacker Value
Unknown

CVE-2014-9250

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.
0
Attacker Value
Unknown

CVE-2014-6260

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of service (paging outage) by leveraging an unattended workstation, aka ZEN-15412.
0
Attacker Value
Unknown

CVE-2014-6257

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper method, aka ZEN-15407.
0
Attacker Value
Unknown

CVE-2014-9252

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416.
0
Attacker Value
Unknown

CVE-2014-9385

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger arbitrary code execution via a ZenPack upload, aka ZEN-15388.
0
Attacker Value
Unknown

CVE-2014-6259

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka ZEN-15414, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2014-6253

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arbitrary users, aka ZEN-12653.
0
Attacker Value
Unknown

CVE-2014-9245

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382.
0
Attacker Value
Unknown

CVE-2014-6258

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering an arbitrary regular-expression match attempt, aka ZEN-15411.
0