Логотип exploitDog
bind:CVE-2023-45139
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-45139

Количество 5

Количество 5

ubuntu логотип

CVE-2023-45139

около 2 лет назад

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-45139

около 2 лет назад

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-45139

около 2 лет назад

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-45139

около 2 лет назад

fontTools is a library for manipulating fonts, written in Python. The ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6673-4983-2vx5

около 2 лет назад

fonttools XML External Entity Injection (XXE) Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-45139

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-45139

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-45139

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-45139

fontTools is a library for manipulating fonts, written in Python. The ...

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-6673-4983-2vx5

fonttools XML External Entity Injection (XXE) Vulnerability

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу