pypi

5,097 tracked vulnerabilities.

CVE-2012-5625
OpenStack Compute (Nova) Folsom <2012.2.2 - Info Disclosure
Dec 26, 2012
EPSS 0.02
CVE-2012-5571 MEDIUM
OpenStack Keystone Essex/Folsom - Auth Bypass
Dec 18, 2012
CVSS 5.4
EPSS 0.02
CVE-2012-5563
OpenStack Keystone < 8.0.0 - Authenticated Authorization Bypass via Token Chaining
Dec 18, 2012
EPSS 0.03
CVE-2012-4571
Python Keyring 0.9.1 - Info Disclosure
Nov 30, 2012
EPSS 0.00
CVE-2012-4520
Django 1.3-1.3.4 and 1.4-1.4.2 - Arbitrary URL Generation via Host Header
Nov 18, 2012
EPSS 0.04
CVE-2012-5482
OpenStack Glance Grizzly/Folsom/Essex - RCE
Nov 11, 2012
EPSS 0.03
CVE-2012-4573
OpenStack Glance <2012.2 - Auth Bypass
Nov 11, 2012
EPSS 0.03
CVE-2012-5825
tweepy - SSL Certificate Hostname Validation Bypass via Missing CN/subjectAltName Check
Nov 04, 2012
EPSS 0.01
CVE-2012-3446 MEDIUM
Apache Libcloud < 0.11.1 - Improper Certificate Validation
Nov 04, 2012
CVSS 5.9
EPSS 0.01
CVE-2012-4406 CRITICAL
OpenStack Swift < 1.7.0 - Remote Code Execution via Unsafe Pickle Deserialization
Oct 22, 2012
CVSS 9.8
EPSS 0.07
CVE-2012-4457
OpenStack Keystone Essex < 2012.1.2 and Folsom < folsom-3 - Authenticated Improper Authentication
Oct 09, 2012
EPSS 0.02
CVE-2012-4456
OpenStack Keystone < 2012.1.2 - Improper Authentication via X-Auth-Token Validation
Oct 09, 2012
EPSS 0.04
CVE-2012-4413
OpenStack Keystone < 2012.1.3 - Authenticated Privilege Retention via Token Invalidation Bypass
Sep 18, 2012
EPSS 0.02
CVE-2012-3458
Beaker < 1.6.4 - Sensitive Session Data Exposure via ECB Mode Encryption
Sep 15, 2012
EPSS 0.02
CVE-2012-4404
MoinMoin 1.9-1.9.4 - Authenticated Group Membership Bypass via Virtual Group Names
Sep 10, 2012
EPSS 0.02
CVE-2012-3542
OpenStack Keystone < 2012.1 - Unauthenticated User Addition to Arbitrary Tenant via Default Tenant Update
Sep 05, 2012
EPSS 0.02
CVE-2012-2146
Elixir 0.8.0 - Information Disclosure via Weak Blowfish IV
Aug 26, 2012
EPSS 0.02
CVE-2012-1176
PyFriBidi < 0.11.0 - Buffer Overflow in fribidi_utf8_to_unicode Function
Aug 26, 2012
EPSS 0.03
CVE-2012-3447
OpenStack Nova 2012.1.x < 2012.1.2 and Folsom < Folsom-3 - Authenticated Arbitrary File Overwrite via Symlink Attack
Aug 20, 2012
EPSS 0.02
CVE-2012-1585
OpenStack Compute (Nova) < 2011.3 - Authenticated Denial of Service via Long Server Name
Aug 17, 2012
EPSS 0.02
CVE-2012-3444
Django < 1.3.2 and 1.4.x < 1.4.1 - Denial of Service via Large TIFF Image Processing
Jul 31, 2012
EPSS 0.02
CVE-2012-3443
Django < 1.3.2 and 1.4.x < 1.4.1 - Denial of Service via ImageField Decompression
Jul 31, 2012
EPSS 0.03
CVE-2012-3442
Django < 1.3.2 and 1.4.x < 1.4.1 - Cross-Site Scripting via Data URL Redirect
Jul 31, 2012
EPSS 0.02
CVE-2012-3426
OpenStack Keystone < 2012.1.1 - Authenticated Token Expiration Bypass via Token Chaining
Jul 31, 2012
EPSS 0.02
CVE-2012-3361
OpenStack Compute (Nova) Diablo Essex Folsom - Authenticated Arbitrary File Write via Symlink Attack
Jul 22, 2012
EPSS 0.03