Количество 60
Количество 60
openSUSE-SU-2021:0270-1
Security update for python
SUSE-SU-2021:0529-1
Security update for python3
SUSE-SU-2021:0432-1
Security update for python
SUSE-SU-2021:0428-1
Security update for python36
SUSE-SU-2021:0355-1
Security update for python
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
CVE-2020-27783
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The ...
CVE-2020-26116
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
CVE-2020-26116
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
CVE-2020-26116
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
CVE-2020-26116
http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
CVE-2020-26116
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x be ...
SUSE-SU-2022:3461-1
Security update for python3-lxml
SUSE-SU-2022:3460-1
Security update for python3-lxml
RLSA-2021:1898
Moderate: python-lxml security update
GHSA-pgww-xf46-h92r
lxml vulnerable to Cross-site Scripting
ELSA-2021-1898
ELSA-2021-1898: python-lxml security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2021:0270-1 Security update for python | больше 5 лет назад | |||
SUSE-SU-2021:0529-1 Security update for python3 | больше 5 лет назад | |||
SUSE-SU-2021:0432-1 Security update for python | больше 5 лет назад | |||
SUSE-SU-2021:0428-1 Security update for python36 | больше 5 лет назад | |||
SUSE-SU-2021:0355-1 Security update for python | больше 5 лет назад | |||
CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code. | CVSS3: 6.1 | 4% Низкий | больше 5 лет назад | |
CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code. | CVSS3: 6.1 | 4% Низкий | почти 6 лет назад | |
CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code. | CVSS3: 6.1 | 4% Низкий | больше 5 лет назад | |
CVSS3: 6.1 | 4% Низкий | около 5 лет назад | ||
CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The ... | CVSS3: 6.1 | 4% Низкий | больше 5 лет назад | |
CVE-2020-26116 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | CVSS3: 7.2 | 6% Низкий | почти 6 лет назад | |
CVE-2020-26116 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | CVSS3: 6.5 | 6% Низкий | больше 6 лет назад | |
CVE-2020-26116 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | CVSS3: 7.2 | 6% Низкий | почти 6 лет назад | |
CVE-2020-26116 http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | CVSS3: 7.2 | 6% Низкий | больше 5 лет назад | |
CVE-2020-26116 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x be ... | CVSS3: 7.2 | 6% Низкий | почти 6 лет назад | |
SUSE-SU-2022:3461-1 Security update for python3-lxml | 4% Низкий | почти 4 года назад | ||
SUSE-SU-2022:3460-1 Security update for python3-lxml | 4% Низкий | почти 4 года назад | ||
RLSA-2021:1898 Moderate: python-lxml security update | 4% Низкий | около 5 лет назад | ||
GHSA-pgww-xf46-h92r lxml vulnerable to Cross-site Scripting | CVSS3: 6.1 | 4% Низкий | больше 5 лет назад | |
ELSA-2021-1898 ELSA-2021-1898: python-lxml security update (MODERATE) | около 5 лет назад |
Уязвимостей на страницу