Логотип exploitDog
bind:"CVE-2018-19787"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2018-19787"

Количество 10

Количество 10

ubuntu логотип

CVE-2018-19787

больше 6 лет назад

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-19787

почти 7 лет назад

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2018-19787

больше 6 лет назад

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2018-19787

около 4 лет назад

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-19787

больше 6 лет назад

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in th ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp26-p53h-6h2p

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2019-02732

больше 6 лет назад

Уязвимость компонента lxml/html/clean.py модуля lxml.html.clean библиотеки для обработки разметки XML и HTML Lxml, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0803-1

больше 3 лет назад

Security update for python-lxml

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0895-1

больше 3 лет назад

Security update for python-lxml

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0803-1

больше 3 лет назад

Security update for python-lxml

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-19787

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-19787

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 4.7
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-19787

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
msrc логотип
CVSS3: 6.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2018-19787

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in th ...

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
github логотип
GHSA-xp26-p53h-6h2p

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-02732

Уязвимость компонента lxml/html/clean.py модуля lxml.html.clean библиотеки для обработки разметки XML и HTML Lxml, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0803-1

Security update for python-lxml

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0895-1

Security update for python-lxml

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0803-1

Security update for python-lxml

больше 3 лет назад

Уязвимостей на страницу