Логотип exploitDog
bind:"CVE-2015-20107" OR bind:"CVE-2021-28861"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2015-20107" OR bind:"CVE-2021-28861"

Количество 49

Количество 49

rocky логотип

RLSA-2022:8353

почти 3 года назад

Moderate: python3.9 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8353

почти 3 года назад

ELSA-2022-8353: python3.9 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-28861

около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2021-28861

около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2021-28861

около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-28861

около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2021-28861

около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-20107

больше 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2015-20107

больше 10 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2015-20107

больше 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2015-20107

больше 3 лет назад

In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2015-20107

больше 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3940-1

почти 3 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3593-1

около 3 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3553-1

около 3 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3544-1

около 3 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3512-2

около 3 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3512-1

около 3 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3511-2

около 3 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3511-1

около 3 лет назад

Security update for python3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2022:8353

Moderate: python3.9 security, bug fix, and enhancement update

почти 3 года назад
oracle-oval логотип
ELSA-2022-8353

ELSA-2022-8353: python3.9 security, bug fix, and enhancement update (MODERATE)

почти 3 года назад
ubuntu логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
1%
Низкий
около 3 лет назад
debian логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

CVSS3: 7.4
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9

CVSS3: 7.6
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3940-1

Security update for python

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3593-1

Security update for python3

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3553-1

Security update for python

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3544-1

Security update for python3

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3512-2

Security update for python

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3512-1

Security update for python

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3511-2

Security update for python3

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3511-1

Security update for python3

1%
Низкий
около 3 лет назад

Уязвимостей на страницу