Количество 72
Количество 72
SUSE-SU-2026:3855-1
Security update for python36
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVE-2026-4786
Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...
ROS-20260728-80-0020
Уязвимость python-PyPDF2
GHSA-2755-2mm4-rm5c
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
BDU:2026-13663
Уязвимость метода http.cookies.Morsel.js_output() интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольный код
ROS-20260623-80-0025
Уязвимость python3.13
ROS-20260623-80-0024
Уязвимость python3.12
ROS-20260623-80-0023
Уязвимость python3.11
ROS-20260623-80-0022
Уязвимость python3.10
ROS-20260623-80-0021
Уязвимость python3.9
ROS-20260623-80-0020
Уязвимость python3.8
GHSA-cccx-m78h-m3xw
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
ELSA-2026-35838
ELSA-2026-35838: python3 security update (IMPORTANT)
ELSA-2026-19589
ELSA-2026-19589: python security update (IMPORTANT)
BDU:2026-09777
Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды
SUSE-SU-2026:3648-1
Security update for python311
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2026:3855-1 Security update for python36 | 17 дней назад | |||
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | 0% Низкий | 5 месяцев назад | ||
CVE-2026-4786 Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ... | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
ROS-20260728-80-0020 Уязвимость python-PyPDF2 | CVSS3: 3.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-2755-2mm4-rm5c http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
BDU:2026-13663 Уязвимость метода http.cookies.Morsel.js_output() интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольный код | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
ROS-20260623-80-0025 Уязвимость python3.13 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0024 Уязвимость python3.12 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0023 Уязвимость python3.11 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0022 Уязвимость python3.10 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0021 Уязвимость python3.9 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0020 Уязвимость python3.8 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-cccx-m78h-m3xw Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
ELSA-2026-35838 ELSA-2026-35838: python3 security update (IMPORTANT) | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-19589 ELSA-2026-19589: python security update (IMPORTANT) | 0% Низкий | 3 месяца назад | ||
BDU:2026-09777 Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:3648-1 Security update for python311 | 26 дней назад |
Уязвимостей на страницу