Логотип exploitDog
bind:"BDU:2025-04572" OR bind:"CVE-2025-0938"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-04572" OR bind:"CVE-2025-0938"

Количество 23

Количество 23

fstec логотип

BDU:2025-04572

5 месяцев назад

Уязвимость функций urllib.parse.urlsplit() и urlparse() интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0938

5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

EPSS: Низкий
redhat логотип

CVE-2025-0938

5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-0938

5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

EPSS: Низкий
msrc логотип

CVE-2025-0938

3 месяца назад

EPSS: Низкий
debian логотип

CVE-2025-0938

5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `url ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0814-1

3 месяца назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0756-1

4 месяца назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0554-1

4 месяца назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0553-1

4 месяца назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0552-1

4 месяца назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0551-1

4 месяца назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0514-1

4 месяца назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0434-1

4 месяца назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0419-1

4 месяца назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0406-1

4 месяца назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0386-1

4 месяца назад

Security update for python39

EPSS: Низкий
redos логотип

ROS-20250402-01

3 месяца назад

Уязвимость python3

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-5qjr-cj9f-phrx

5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7109

около 1 месяца назад

ELSA-2025-7109: python3.11 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-04572

Уязвимость функций urllib.parse.urlsplit() и urlparse() интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-0938

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

1%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-0938

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

CVSS3: 6.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-0938

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

1%
Низкий
5 месяцев назад
msrc логотип
1%
Низкий
3 месяца назад
debian логотип
CVE-2025-0938

The Python standard library functions `urllib.parse.urlsplit` and `url ...

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0814-1

Security update for python

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0756-1

Security update for python

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0554-1

Security update for python3

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0553-1

Security update for python

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0552-1

Security update for python3

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0551-1

Security update for python311

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0514-1

Security update for python

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0434-1

Security update for python36

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0419-1

Security update for python311

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0406-1

Security update for python310

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0386-1

Security update for python39

1%
Низкий
4 месяца назад
redos логотип
ROS-20250402-01

Уязвимость python3

CVSS3: 6.8
1%
Низкий
3 месяца назад
github логотип
GHSA-5qjr-cj9f-phrx

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

1%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-7109

ELSA-2025-7109: python3.11 security update (MODERATE)

около 1 месяца назад

Уязвимостей на страницу