Zenoss Core

CPE Details

Zenoss Core
-
2020-02-20
19h24 +00:00
2020-02-20
19h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:zenoss:zenoss_core:-:*:*:*:*:*:*:*

Informations

Vendor

zenoss

Product

zenoss_core

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-6262 2020-02-12 00h30 +00:00 Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
7.5
High
CVE-2014-6255 2014-12-15 16h27 +00:00 Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the came_from parameter, aka ZEN-11998.
6.4
CVE-2014-9249 2014-12-15 16h27 +00:00 The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408.
7.5
CVE-2014-9386 2014-12-15 16h27 +00:00 Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
6.8