Количество 1 113
Количество 1 113
ELSA-2020-3911
ELSA-2020-3911: python security update (MODERATE)
ELSA-2019-4884
ELSA-2019-4884: python security update (IMPORTANT)
ELSA-2019-4877
ELSA-2019-4877: python security update (IMPORTANT)
ELSA-2019-4876
ELSA-2019-4876: python security update (IMPORTANT)
ELSA-2017-1868
ELSA-2017-1868: python security and bug fix update (MODERATE)
ELSA-2016-2586
ELSA-2016-2586: python security, bug fix, and enhancement update (LOW)
ELSA-2013-1582
ELSA-2013-1582: python security, bug fix, and enhancement update (MODERATE)
CVE-2026-7210
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
CVE-2026-7210
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
CVE-2026-7210
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
CVE-2026-7210
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ...
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and ...
CVE-2026-4519
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().
CVE-2026-4519
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().
CVE-2026-4519
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().
CVE-2026-4519
The webbrowser.open() API would accept leading dashes in the URL which ...
CVE-2026-4360
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2020-3911 ELSA-2020-3911: python security update (MODERATE) | 5% Низкий | почти 6 лет назад | ||
ELSA-2019-4884 ELSA-2019-4884: python security update (IMPORTANT) | 4% Низкий | почти 7 лет назад | ||
ELSA-2019-4877 ELSA-2019-4877: python security update (IMPORTANT) | 4% Низкий | почти 7 лет назад | ||
ELSA-2019-4876 ELSA-2019-4876: python security update (IMPORTANT) | 4% Низкий | почти 7 лет назад | ||
ELSA-2017-1868 ELSA-2017-1868: python security and bug fix update (MODERATE) | 3% Низкий | около 9 лет назад | ||
ELSA-2016-2586 ELSA-2016-2586: python security, bug fix, and enhancement update (LOW) | 25% Средний | почти 10 лет назад | ||
ELSA-2013-1582 ELSA-2013-1582: python security, bug fix, and enhancement update (MODERATE) | 5% Низкий | почти 13 лет назад | ||
CVE-2026-7210 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-7210 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-7210 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-7210 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ... | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and ... | CVSS3: 6.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-4519 The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). | CVSS3: 3.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-4519 The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). | CVSS3: 7.1 | 0% Низкий | 6 месяцев назад | |
CVE-2026-4519 The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). | CVSS3: 3.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-4519 The webbrowser.open() API would accept leading dashes in the URL which ... | CVSS3: 3.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-4360 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу