Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 751

Количество 751

ubuntu логотип

CVE-2015-0222

около 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0222

около 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0222

около 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0222

около 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0221

около 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0221

около 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0221

около 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0221

около 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x befo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0220

около 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0220

около 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0220

около 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0220

около 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0219

около 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0219

около 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2015-0219

около 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0219

около 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-3730

больше 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-3730

больше 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-3730

больше 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-3730

больше 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
6%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
6%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
6%
Низкий
около 11 лет назад
debian логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
6%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
9%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
9%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
9%
Низкий
около 11 лет назад
debian логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x befo ...

CVSS2: 5
9%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
около 11 лет назад
debian логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
3%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-0219

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5
3%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-0219

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5.8
3%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-0219

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

CVSS2: 5
3%
Низкий
около 11 лет назад
debian логотип
CVE-2015-0219

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allo ...

CVSS2: 5
3%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-3730

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-3730

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3730

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-3730

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, ...

CVSS2: 4.3
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу