Tagged “pip”
CVEs tagged pip, newest first.
4682 CVEsRSS
CVE-2019-16785High· 7.1HTTP Request Smuggling: LF vs CRLF handling in Waitress
HTTP Request Smuggling: LF vs CRLF handling in Waitress
CVE-2019-16786High· 7.1HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
CVE-2019-16792CriticalHTTP Request Smuggling: Content-Length Sent Twice in Waitress
HTTP Request Smuggling: Content-Length Sent Twice in Waitress
CVE-2019-16778Low· 2.6Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
CVE-2019-16766High· 8.72FA bypass in Wagtail through new device path
2FA bypass in Wagtail through new device path
CVE-2019-12417Medium· 4.8Apache Airflow vulnerable to XSS and local file disclosure
Apache Airflow vulnerable to XSS and local file disclosure
CVE-2017-18638High· 7.5PoCgraphite.composer.views.send_email vulnerable to SSRF
graphite.composer.views.send_email vulnerable to SSRF
CVE-2019-10751High· 8.8Open Redirect in httpie
Open Redirect in httpie
CVE-2019-1020003Medium· 5.4Cross-site scripting invenio-records
Cross-site scripting invenio-records
CVE-2019-1020005Medium· 5.4Cross-site Scripting in invenio-communities
Cross-site Scripting in invenio-communities
CVE-2019-1020019Medium· 6.1Cross-site Scripting in invenio-previewer
Cross-site Scripting in invenio-previewer
CVE-2019-1020006Medium· 6.1Invenio-App vulnerable to host header injection attack
Invenio-App vulnerable to host header injection attack
CVE-2019-16791Medium· 6.9postfix-mta-sts-resolver Algorithm Downgrade vulnerability
postfix-mta-sts-resolver Algorithm Downgrade vulnerability
CVE-2019-13177Critical· 9.8Improper Verification of Cryptographic Signature in django-rest-registration
Improper Verification of Cryptographic Signature in django-rest-registration
CVE-2019-10255Medium· 6.1Open Redirect vulnerability in jupyterhub and notebook
Open Redirect vulnerability in jupyterhub and notebook
CVE-2018-13796Medium· 6.5Moderate severity vulnerability that affects mailman
Moderate severity vulnerability that affects mailman
CVE-2011-1948Medium· 6.1Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
CVE-2011-1950Medium· 6.5⚠ ExploitedPlone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
CVE-2010-1104MediumModerate severity vulnerability that affects Zope2
Moderate severity vulnerability that affects Zope2
CVE-2009-0662MediumModerate severity vulnerability that affects Products.PlonePAS
Moderate severity vulnerability that affects Products.PlonePAS
CVE-2011-2528HighHigh severity vulnerability that affects Plone and Zope2
High severity vulnerability that affects Plone and Zope2
CVE-2017-2673High· 7.2An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…
CVE-2018-1000164High· 7.5Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
CVE-2018-1000516Medium· 6.1The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in …
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow f…
CVE-2016-6903Critical· 9.9lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
CVE-2016-6902Critical· 9.9lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
CVE-2017-7200Medium· 5.8An SSRF issue was discovered in OpenStack Glance before Newton
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-0006NoneThe TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.