Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2016-0772

около 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2016-0772

больше 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
EPSS: Средний
nvd логотип

CVE-2016-0772

около 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2016-0772

около 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-6m57-q338-h677

больше 4 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2016:1885-1

около 10 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2270-1

около 10 лет назад

Security update for python

EPSS: Низкий
oracle-oval логотип

ELSA-2016-1626

около 10 лет назад

ELSA-2016-1626: python security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2859-1

почти 10 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2653-1

почти 10 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2106-1

около 10 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:2120-1

около 10 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0223-1

больше 7 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0086-1

больше 6 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0114-1

больше 6 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0234-1

больше 6 лет назад

Security update for python

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
около 10 лет назад
redhat логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
15%
Средний
больше 10 лет назад
nvd логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
около 10 лет назад
debian логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
15%
Средний
около 10 лет назад
github логотип
GHSA-6m57-q338-h677

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1885-1

Security update for python

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2270-1

Security update for python

около 10 лет назад
oracle-oval логотип
ELSA-2016-1626

ELSA-2016-1626: python security update (MODERATE)

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2859-1

Security update for python3

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2653-1

Security update for python3

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2106-1

Security update for python

около 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2120-1

Security update for python3

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2019:0223-1

Security update for python

больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0086-1

Security update for python3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0114-1

Security update for python3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0234-1

Security update for python

больше 6 лет назад

Уязвимостей на страницу