CVE-2010-3198
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/09/2010
Last modified:
11/04/2025
Description
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zope:zope:2.10.0-b1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.0-b2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.0-c1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.0-final:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.2-b1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.2-final:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.3-final:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.4-final:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zope:zope:2.10.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/42939
- http://www.vupen.com/english/advisories/2010/2275
- http://www.zope.org/Products/Zope/2.10.12/CHANGES.txt
- http://www.zope.org/Products/Zope/2.11.7/CHANGES.txt
- https://bugs.launchpad.net/zope2/+bug/627988
- https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html
- http://www.securityfocus.com/bid/42939
- http://www.vupen.com/english/advisories/2010/2275
- http://www.zope.org/Products/Zope/2.10.12/CHANGES.txt
- http://www.zope.org/Products/Zope/2.11.7/CHANGES.txt
- https://bugs.launchpad.net/zope2/+bug/627988
- https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html



