Логотип exploitDog
bind:"CVE-2022-0391" OR bind:"CVE-2015-20107"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-0391" OR bind:"CVE-2015-20107"

Количество 45

Количество 45

oracle-oval логотип

ELSA-2022-6457

почти 3 года назад

ELSA-2022-6457: python3 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2022-0391

больше 3 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-0391

около 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-0391

больше 3 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-0391

больше 3 лет назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-0391

больше 3 лет назад

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2015-20107

почти 10 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2015-20107

около 3 лет назад

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2015-20107

около 3 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-75jm-2xrg-5wpf

больше 3 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

EPSS: Низкий
fstec логотип

BDU:2022-02302

больше 3 лет назад

Уязвимость модуля urllib.parse интерпретатора языка программирования Python, позволяющая нарушителю внедрить произвольные данные в ответ сервера

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2357-1

почти 3 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2344-1

почти 3 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2291-1

почти 3 года назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2249-1

почти 3 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2248-1

почти 3 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2174-1

почти 3 года назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2166-1

почти 3 года назад

Security update for python3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-6457

ELSA-2022-6457: python3 security update (MODERATE)

почти 3 года назад
ubuntu логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
1%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 7.6
1%
Низкий
около 3 лет назад
debian логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-75jm-2xrg-5wpf

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-02302

Уязвимость модуля urllib.parse интерпретатора языка программирования Python, позволяющая нарушителю внедрить произвольные данные в ответ сервера

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2357-1

Security update for python3

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2344-1

Security update for python

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2291-1

Security update for python310

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2249-1

Security update for python

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2248-1

Security update for python

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2174-1

Security update for python39

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2166-1

Security update for python3

1%
Низкий
почти 3 года назад

Уязвимостей на страницу