4.3

CVE-2010-3495

Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

Data is provided by the National Vulnerability Database (NVD)
ZopeZodb Version <= 3.9.7
ZopeZodb Version2.8.11
ZopeZodb Version2.9.11
ZopeZodb Version2.10.9
ZopeZodb Version2.11.4
ZopeZodb Version3.1
ZopeZodb Version3.1.1
ZopeZodb Version3.2
ZopeZodb Version3.2.4
ZopeZodb Version3.3
ZopeZodb Version3.3.3
ZopeZodb Version3.4
ZopeZodb Version3.4.1
ZopeZodb Version3.5
ZopeZodb Version3.6
ZopeZodb Version3.7
ZopeZodb Version3.8
ZopeZodb Version3.8.0
ZopeZodb Version3.8.1
ZopeZodb Version3.8.2
ZopeZodb Version3.8.6
ZopeZodb Version3.9.0
ZopeZodb Version3.9.0b1
ZopeZodb Version3.9.0b2
ZopeZodb Version3.9.0b3
ZopeZodb Version3.9.0b4
ZopeZodb Version3.9.0b5
ZopeZodb Version3.9.0c1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.04% 0.754
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.