Логотип exploitDog
bind:"CVE-2021-28861" OR bind:"CVE-2015-20107"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-28861" OR bind:"CVE-2015-20107"

Количество 49

Количество 49

rocky логотип

RLSA-2022:8353

больше 2 лет назад

Moderate: python3.9 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8353

больше 2 лет назад

ELSA-2022-8353: python3.9 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-28861

почти 3 года назад

** DISPUTED ** Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2021-28861

почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2021-28861

почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-28861

почти 3 года назад

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2021-28861

почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2015-20107

почти 10 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2015-20107

около 3 лет назад

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3940-1

больше 2 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3593-1

больше 2 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3553-1

больше 2 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3544-1

больше 2 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3512-2

больше 2 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3512-1

больше 2 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3511-2

больше 2 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3511-1

больше 2 лет назад

Security update for python3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2022:8353

Moderate: python3.9 security, bug fix, and enhancement update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8353

ELSA-2022-8353: python3.9 security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
ubuntu логотип
CVE-2021-28861

** DISPUTED ** Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

CVSS3: 7.4
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 7.6
1%
Низкий
около 3 лет назад
debian логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3940-1

Security update for python

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3593-1

Security update for python3

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3553-1

Security update for python

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3544-1

Security update for python3

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3512-2

Security update for python

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3512-1

Security update for python

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3511-2

Security update for python3

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3511-1

Security update for python3

0%
Низкий
больше 2 лет назад

Уязвимостей на страницу