Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2020-11001Medium· 5.8Possible XSS attack in Wagtail
Possible XSS attack in Wagtail
CVE-2020-6817High· 7.5regular expression denial-of-service (ReDoS) in Bleach
regular expression denial-of-service (ReDoS) in Bleach
CVE-2020-6816Medium· 6.1Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
CVE-2020-5252Medium· 5.0Malicious package may avoid detection in python auditing
Malicious package may avoid detection in python auditing
CVE-2020-5262High· 7.7GitHub personal access token leaking into temporary EasyBuild (debug) logs
GitHub personal access token leaking into temporary EasyBuild (debug) logs
CVE-2020-10571Critical· 9.8Potential buffer overflow in psd-tools
Potential buffer overflow in psd-tools
CVE-2020-5240High· 7.62FA bypass through deleting devices in wagtail-2fa
2FA bypass through deleting devices in wagtail-2fa
CVE-2020-6802Medium· 6.1XSS in Bleach when noscript and raw tag whitelisted
XSS in Bleach when noscript and raw tag whitelisted
CVE-2020-5236Medium· 5.7PoCCatastrophic backtracking in regex allows Denial of Service in Waitress
Catastrophic backtracking in regex allows Denial of Service in Waitress
CVE-2020-5215Medium· 5.0Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
CVE-2020-5227Medium· 4.4Feedgen Vulnerable to XML Denial of Service Attacks
Feedgen Vulnerable to XML Denial of Service Attacks
CVE-2020-5224Medium· 6.5Session key exposure through session list in Django User Sessions
Session key exposure through session list in Django User Sessions
CVE-2019-16784High· 7.0PoCLocal Privilege Escalation in PyInstaller
Local Privilege Escalation in PyInstaller
CVE-2020-35858Critical· 9.8Parsing a specially crafted message can result in a stack overflow
Parsing a specially crafted message can result in a stack overflow
CVE-2019-16785High· 7.1HTTP Request Smuggling: LF vs CRLF handling in Waitress
HTTP Request Smuggling: LF vs CRLF handling in Waitress
CVE-2019-16786High· 7.1HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
CVE-2019-16792CriticalHTTP Request Smuggling: Content-Length Sent Twice in Waitress
HTTP Request Smuggling: Content-Length Sent Twice in Waitress
CVE-2019-16778Low· 2.6Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
CVE-2019-16766High· 8.72FA bypass in Wagtail through new device path
2FA bypass in Wagtail through new device path
CVE-2019-12417Medium· 4.8Apache Airflow vulnerable to XSS and local file disclosure
Apache Airflow vulnerable to XSS and local file disclosure
CVE-2017-18638High· 7.5PoCgraphite.composer.views.send_email vulnerable to SSRF
graphite.composer.views.send_email vulnerable to SSRF
CVE-2019-10751High· 8.8Open Redirect in httpie
Open Redirect in httpie
CVE-2019-15554Critical· 9.8Memory corruption in SmallVec::grow()
Memory corruption in SmallVec::grow()
CVE-2019-1020003Medium· 5.4Cross-site scripting invenio-records
Cross-site scripting invenio-records
CVE-2019-1020005Medium· 5.4Cross-site Scripting in invenio-communities
Cross-site Scripting in invenio-communities
CVE-2019-1020019Medium· 6.1Cross-site Scripting in invenio-previewer
Cross-site Scripting in invenio-previewer
CVE-2019-1020006Medium· 6.1Invenio-App vulnerable to host header injection attack
Invenio-App vulnerable to host header injection attack
CVE-2019-16791Medium· 6.9postfix-mta-sts-resolver Algorithm Downgrade vulnerability
postfix-mta-sts-resolver Algorithm Downgrade vulnerability
CVE-2019-13177Critical· 9.8Improper Verification of Cryptographic Signature in django-rest-registration
Improper Verification of Cryptographic Signature in django-rest-registration
CVE-2019-15551Critical· 9.8Double-free and use-after-free in SmallVec::grow()
Double-free and use-after-free in SmallVec::grow()