Количество 60
Количество 60
RLSA-2026:28581
Important: python3.14 security, bug fix, and enhancement update
RLSA-2026:28247
Important: python3.14 security, bug fix, and enhancement update
ELSA-2026-28581
ELSA-2026-28581: python3.14 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-28247
ELSA-2026-28247: python3.14 security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3132-1
Security update for python311
SUSE-SU-2026:3104-1
Security update for python311
SUSE-SU-2026:2055-1
Security update for python312
SUSE-SU-2026:2464-1
Security update for python313
SUSE-SU-2026:1947-1
Security update for python310
SUSE-SU-2026:1937-1
Security update for python3
SUSE-SU-2026:2387-1
Security update for python
SUSE-SU-2026:1818-1
Security update for python39
SUSE-SU-2026:2664-1
Security update for python, python-base, python-doc
SUSE-SU-2026:1715-1
Security update for python3
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
BaseCookie.js_output() does not neutralize embedded characters
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and ...
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:28581 Important: python3.14 security, bug fix, and enhancement update | около 1 месяца назад | |||
RLSA-2026:28247 Important: python3.14 security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-28581 ELSA-2026-28581: python3.14 security, bug fix, and enhancement update (IMPORTANT) | 15 дней назад | |||
ELSA-2026-28247 ELSA-2026-28247: python3.14 security, bug fix, and enhancement update (IMPORTANT) | около 1 месяца назад | |||
SUSE-SU-2026:3132-1 Security update for python311 | 11 дней назад | |||
SUSE-SU-2026:3104-1 Security update for python311 | 14 дней назад | |||
SUSE-SU-2026:2055-1 Security update for python312 | 2 месяца назад | |||
SUSE-SU-2026:2464-1 Security update for python313 | около 1 месяца назад | |||
SUSE-SU-2026:1947-1 Security update for python310 | 2 месяца назад | |||
SUSE-SU-2026:1937-1 Security update for python3 | 2 месяца назад | |||
SUSE-SU-2026:2387-1 Security update for python | около 2 месяцев назад | |||
SUSE-SU-2026:1818-1 Security update for python39 | 3 месяца назад | |||
SUSE-SU-2026:2664-1 Security update for python, python-base, python-doc | около 1 месяца назад | |||
SUSE-SU-2026:1715-1 Security update for python3 | 3 месяца назад | |||
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters | 0% Низкий | около 1 месяца назад | ||
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and ... | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу