Summary
Detail | |||
---|---|---|---|
Vendor | Zope | First view | 2009-09-08 |
Product | Zodb | Last view | 2010-10-19 |
Version | 3.9.0 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:zope:zodb |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.3 | 2010-10-19 | CVE-2010-3495 | Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492. |
6 | 2009-09-08 | CVE-2009-2701 | Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-362 | Race Condition |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
68608 | Zope Object Database (ZODB) ZEO/StorageServer.py Multiple Client Connection R... |
57760 | Zope Object Database (ZODB) Zope Enterprise Objects (ZEO) Server Arbitrary Fi... |
OpenVAS Exploits
id | Description |
---|---|
2010-11-30 | Name : Zope Object Database ZEO Server Denial of Service Vulnerability File : nvt/gb_zodb_zeo_server_dos_vuln.nasl |