Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2015-4706

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.
0
Attacker Value
Unknown

CVE-2015-5607

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Cross-site request forgery in the REST API in IPython 2 and 3.
0
Attacker Value
Unknown

CVE-2016-0772

Disclosure Date: September 02, 2016 (last updated November 25, 2024)
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
0
Attacker Value
Unknown

CVE-2016-5636

Disclosure Date: September 02, 2016 (last updated November 25, 2024)
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-5699

Disclosure Date: September 02, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
0