Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-6m57-q338-h677

около 4 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2016-0772

почти 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2016-0772

около 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
EPSS: Средний
nvd логотип

CVE-2016-0772

почти 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2016-0772

почти 10 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2016:1885-1

около 10 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2270-1

почти 10 лет назад

Security update for python

EPSS: Низкий
oracle-oval логотип

ELSA-2016-1626

почти 10 лет назад

ELSA-2016-1626: python security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2859-1

больше 9 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2653-1

почти 10 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2106-1

почти 10 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:2120-1

почти 10 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0223-1

больше 7 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0086-1

больше 6 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0114-1

больше 6 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0234-1

больше 6 лет назад

Security update for python

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6m57-q338-h677

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
около 4 лет назад
ubuntu логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
почти 10 лет назад
redhat логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
15%
Средний
около 10 лет назад
nvd логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
15%
Средний
почти 10 лет назад
debian логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
15%
Средний
почти 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1885-1

Security update for python

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2270-1

Security update for python

почти 10 лет назад
oracle-oval логотип
ELSA-2016-1626

ELSA-2016-1626: python security update (MODERATE)

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2859-1

Security update for python3

больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:2653-1

Security update for python3

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2106-1

Security update for python

почти 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2120-1

Security update for python3

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2019:0223-1

Security update for python

больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0086-1

Security update for python3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0114-1

Security update for python3

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0234-1

Security update for python

больше 6 лет назад

Уязвимостей на страницу