CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104055  CVE-2017-7235  Candidate  An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.  Assigned (20170323)  None (candidate not yet proposed)    View
104054  CVE-2017-7234  Candidate  A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.  Assigned (20170322)  None (candidate not yet proposed)    View
104053  CVE-2017-7233  Candidate  Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn"t be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.  Assigned (20170322)  None (candidate not yet proposed)    View
104052  CVE-2017-7232  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170322)  None (candidate not yet proposed)    View
104051  CVE-2017-7231  Candidate  pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the "process()" function of the "pngdefry.c" source file.  Assigned (20170322)  None (candidate not yet proposed)    View

Page 133 of 20943, showing 5 records out of 104715 total, starting on record 661, ending on 665

Actions