Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 900

Количество 900

ubuntu логотип

CVE-2015-2316

больше 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-2316

больше 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2316

больше 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-2316

больше 11 лет назад

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-2241

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-2241

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2241

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2241

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the contents function in a ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0222

больше 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0222

больше 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0222

больше 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0222

больше 11 лет назад

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0221

больше 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-0221

больше 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0221

больше 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0221

больше 11 лет назад

The django.views.static.serve view in Django before 1.4.18, 1.6.x befo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0220

больше 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0220

больше 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0220

больше 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0220

больше 11 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
5%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 4.3
5%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

CVSS2: 5
5%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7. ...

CVSS2: 5
5%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2241

Cross-site scripting (XSS) vulnerability in the contents function in a ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

CVSS2: 5
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x befor ...

CVSS2: 5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 4.3
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

CVSS2: 5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x befo ...

CVSS2: 5
4%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0220

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

CVSS2: 4.3
3%
Низкий
больше 11 лет назад

Уязвимостей на страницу