Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

fstec логотип

BDU:2025-03301

больше 2 лет назад

Уязвимость набора инструментов для Python dnspython, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
EPSS: Низкий
redos логотип

ROS-20250226-01

больше 1 года назад

Уязвимость python3-eventlet

CVSS2: 6.6
EPSS: Низкий
redos логотип

ROS-20250212-08

больше 1 года назад

Уязвимость python3-dns

CVSS2: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2023-29483

больше 2 лет назад

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2023-29483

больше 2 лет назад

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2023-29483

больше 2 лет назад

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2023-29483

больше 2 лет назад

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remo ...

CVSS3: 7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3298-1

почти 2 года назад

Security update for python-dnspython

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3297-1

почти 2 года назад

Security update for python-dnspython

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2655-1

около 2 лет назад

Security update for python-dnspython

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2626-1

около 2 лет назад

Security update for python-dnspython

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2605-1

около 2 лет назад

Security update for python-dnspython

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2026:2816-1

24 дня назад

Recommended update for python-aioresponses, python-google-api-core, python-google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-google-cloud-artifact-registry, python-google-cloud-audit-log, python-google-cloud-build, python-google-cloud-compute, python-google-cloud-core, python-google-cloud-dns, python-google-cloud-domains, python-google-cloud-iam, python-google-cloud-kms, python-google-cloud-kms-inventory, python-google-cloud-logging, python-google-cloud-run, python-google-cloud-secret-manager, python-google-cloud-service-directory, python-google-cloud-spanner, python-google-cloud-storage, python-google-cloud-vpc-access, python-google-crc32c, python-google-resumable-media, python-googleapis-common-protos, python-grpc-google-iam-v1, python-grpc-interceptor, python-mmh3, python-mypy, python-opentelemetry-resourcedetector-gcp, python-poetry-core, python-proto-plus, python-pytest-asyncio, python-syrupy, python-typed-ast, python-uritemplate, python-dnspython, python-trio, python-websocket-client

EPSS: Низкий
rocky логотип

RLSA-2024:9423

больше 1 года назад

Moderate: python-dns security update

EPSS: Низкий
rocky логотип

RLSA-2024:3275

около 2 лет назад

Moderate: python-dns security update

EPSS: Низкий
github логотип

GHSA-3rq5-2g8h-59hc

больше 2 лет назад

Potential DoS via the Tudoor mechanism in eventlet and dnspython

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9423

больше 1 года назад

ELSA-2024-9423: python-dns security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3275

около 2 лет назад

ELSA-2024-3275: python-dns security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03301

Уязвимость набора инструментов для Python dnspython, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
2%
Низкий
больше 2 лет назад
redos логотип
ROS-20250226-01

Уязвимость python3-eventlet

CVSS2: 6.6
2%
Низкий
больше 1 года назад
redos логотип
ROS-20250212-08

Уязвимость python3-dns

CVSS2: 6.6
2%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 7
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 5.9
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVSS3: 7
2%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remo ...

CVSS3: 7
2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:3298-1

Security update for python-dnspython

2%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3297-1

Security update for python-dnspython

2%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:2655-1

Security update for python-dnspython

2%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:2626-1

Security update for python-dnspython

2%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:2605-1

Security update for python-dnspython

2%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-RU-2026:2816-1

Recommended update for python-aioresponses, python-google-api-core, python-google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-google-cloud-artifact-registry, python-google-cloud-audit-log, python-google-cloud-build, python-google-cloud-compute, python-google-cloud-core, python-google-cloud-dns, python-google-cloud-domains, python-google-cloud-iam, python-google-cloud-kms, python-google-cloud-kms-inventory, python-google-cloud-logging, python-google-cloud-run, python-google-cloud-secret-manager, python-google-cloud-service-directory, python-google-cloud-spanner, python-google-cloud-storage, python-google-cloud-vpc-access, python-google-crc32c, python-google-resumable-media, python-googleapis-common-protos, python-grpc-google-iam-v1, python-grpc-interceptor, python-mmh3, python-mypy, python-opentelemetry-resourcedetector-gcp, python-poetry-core, python-proto-plus, python-pytest-asyncio, python-syrupy, python-typed-ast, python-uritemplate, python-dnspython, python-trio, python-websocket-client

2%
Низкий
24 дня назад
rocky логотип
RLSA-2024:9423

Moderate: python-dns security update

2%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:3275

Moderate: python-dns security update

2%
Низкий
около 2 лет назад
github логотип
GHSA-3rq5-2g8h-59hc

Potential DoS via the Tudoor mechanism in eventlet and dnspython

CVSS3: 5.9
2%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-9423

ELSA-2024-9423: python-dns security update (MODERATE)

2%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-3275

ELSA-2024-3275: python-dns security update (MODERATE)

2%
Низкий
около 2 лет назад

Уязвимостей на страницу