Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 113

Количество 1 113

suse-cvrf логотип

SUSE-SU-2017:0726-1

больше 9 лет назад

Security update for java-1_6_0-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0720-1

больше 9 лет назад

Security update for java-1_7_1-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0719-1

больше 9 лет назад

Security update for java-1_7_1-ibm

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2017:0716-1

больше 9 лет назад

Security update for java-1_7_0-ibm

EPSS: Критический
github логотип

GHSA-wj55-vqcq-gxcp

больше 4 лет назад

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w2rw-pv8p-h9c8

больше 4 лет назад

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-hc96-xw56-vfwh

больше 4 лет назад

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-75jm-2xrg-5wpf

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

EPSS: Низкий
oracle-oval логотип

ELSA-2021-9130

больше 5 лет назад

ELSA-2021-9130: python38:3.8 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-9129

больше 5 лет назад

ELSA-2021-9129: python36:3.6 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-9128

больше 5 лет назад

ELSA-2021-9128: python27:2.7 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-9107

больше 5 лет назад

ELSA-2021-9107: python security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-9101

больше 5 лет назад

ELSA-2021-9101: python3 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-9100

больше 5 лет назад

ELSA-2021-9100: python3 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2021-4057

почти 5 лет назад

ELSA-2021-4057: python3 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2018-2123

около 8 лет назад

ELSA-2018-2123: python security update (MODERATE)

EPSS: Критический
ubuntu логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-0391

больше 5 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2017:0726-1

Security update for java-1_6_0-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0720-1

Security update for java-1_7_1-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0719-1

Security update for java-1_7_1-ibm

96%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0716-1

Security update for java-1_7_0-ibm

96%
Критический
больше 9 лет назад
github логотип
GHSA-wj55-vqcq-gxcp

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-w2rw-pv8p-h9c8

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS3: 7.5
96%
Критический
больше 4 лет назад
github логотип
GHSA-hc96-xw56-vfwh

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

CVSS3: 9.8
23%
Средний
больше 4 лет назад
github логотип
GHSA-75jm-2xrg-5wpf

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

8%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2021-9130

ELSA-2021-9130: python38:3.8 security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-9129

ELSA-2021-9129: python36:3.6 security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-9128

ELSA-2021-9128: python27:2.7 security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-9107

ELSA-2021-9107: python security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-9101

ELSA-2021-9101: python3 security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-9100

ELSA-2021-9100: python3 security update (IMPORTANT)

23%
Средний
больше 5 лет назад
oracle-oval логотип
ELSA-2021-4057

ELSA-2021-4057: python3 security update (MODERATE)

5%
Низкий
почти 5 лет назад
oracle-oval логотип
ELSA-2018-2123

ELSA-2018-2123: python security update (MODERATE)

96%
Критический
около 8 лет назад
ubuntu логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 5.3
8%
Низкий
больше 5 лет назад
nvd логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
8%
Низкий
больше 4 лет назад

Уязвимостей на страницу