Количество 20
Количество 20
CVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
CVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
CVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
CVE-2019-10160
A security regression of CVE-2019-9636 was discovered in python since ...
openSUSE-SU-2019:1906-1
Security update for python
SUSE-SU-2019:2064-1
Security update for python
GHSA-379v-rm3f-c48g
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
ELSA-2019-1587
ELSA-2019-1587: python security update (IMPORTANT)
BDU:2019-02825
Уязвимость функций urllib.parse.urlsplit и urllib.parse.urlparse интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию, читать или записывать произвольные данные, или вызвать отказ в обслуживании
SUSE-SU-2019:2091-1
Security update for python
SUSE-SU-2019:2050-1
Security update for python3
SUSE-SU-2019:14142-1
Security update for python
ELSA-2019-1467
ELSA-2019-1467: python security update (IMPORTANT)
SUSE-SU-2019:2053-2
Security update for python3
SUSE-SU-2019:2053-1
Security update for python3
SUSE-SU-2020:0302-1
Security update for python36
openSUSE-SU-2020:0086-1
Security update for python3
SUSE-SU-2020:0114-1
Security update for python3
SUSE-SU-2020:0234-1
Security update for python
SUSE-SU-2019:14246-1
Security update for Mozilla Firefox
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-2019-10160 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.  | CVSS3: 9.8  | 2% Низкий | больше 6 лет назад | |
CVE-2019-10160 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.  | CVSS3: 9.8  | 2% Низкий | больше 6 лет назад | |
CVE-2019-10160 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.  | CVSS3: 9.8  | 2% Низкий | больше 6 лет назад | |
CVE-2019-10160 A security regression of CVE-2019-9636 was discovered in python since ...  | CVSS3: 9.8  | 2% Низкий | больше 6 лет назад | |
openSUSE-SU-2019:1906-1 Security update for python  | 2% Низкий | около 6 лет назад | ||
SUSE-SU-2019:2064-1 Security update for python  | 2% Низкий | около 6 лет назад | ||
GHSA-379v-rm3f-c48g A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.  | CVSS3: 9.8  | 2% Низкий | больше 3 лет назад | |
ELSA-2019-1587 ELSA-2019-1587: python security update (IMPORTANT)  | больше 6 лет назад | |||
BDU:2019-02825 Уязвимость функций urllib.parse.urlsplit и urllib.parse.urlparse интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию, читать или записывать произвольные данные, или вызвать отказ в обслуживании  | CVSS3: 9.8  | 2% Низкий | больше 6 лет назад | |
SUSE-SU-2019:2091-1 Security update for python  | около 6 лет назад | |||
SUSE-SU-2019:2050-1 Security update for python3  | около 6 лет назад | |||
SUSE-SU-2019:14142-1 Security update for python  | около 6 лет назад | |||
ELSA-2019-1467 ELSA-2019-1467: python security update (IMPORTANT)  | больше 6 лет назад | |||
SUSE-SU-2019:2053-2 Security update for python3  | около 6 лет назад | |||
SUSE-SU-2019:2053-1 Security update for python3  | около 6 лет назад | |||
SUSE-SU-2020:0302-1 Security update for python36  | почти 6 лет назад | |||
openSUSE-SU-2020:0086-1 Security update for python3  | почти 6 лет назад | |||
SUSE-SU-2020:0114-1 Security update for python3  | почти 6 лет назад | |||
SUSE-SU-2020:0234-1 Security update for python  | почти 6 лет назад | |||
SUSE-SU-2019:14246-1 Security update for Mozilla Firefox  | почти 6 лет назад | 
Уязвимостей на страницу