twisted kayıtları
twisted üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-295 Improper Certificate Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-425 Direct Request ('Forced Browsing')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-10108İstismar yok | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Kritik9,8 | — | %4,0 | 12 Mar 2020 |
40Planlayın | CVE-2020-10109İstismar yok | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Kritik9,8 | — | %3,3 | 12 Mar 2020 |
33İzleyin | CVE-2022-24801İstismar yok | HTTP Request Smuggling in twisted.webtwisted · twisted · CWE-444 | Yüksek8,1 | — | %2,8 | 4 Nis 2022 |
33İzleyin | CVE-2024-41671İstismar yok | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | Yüksek8,3 | — | %0,9 | 29 Tem 2024 |
31İzleyin | CVE-2022-21716İstismar yok | Buffer Overflow in Twistedtwisted · twisted · CWE-120 | Yüksek7,5 | — | %3,5 | 3 Mar 2022 |
31İzleyin | CVE-2014-7143İstismar yok | Python Twisted 14.0 trustRoot is not respected in HTTP clienttwisted · twisted · CWE-295 | Yüksek7,5 | — | %2,6 | 12 Kas 2019 |
30İzleyin | CVE-2019-12855İstismar yok | In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attatwisted · twisted · CWE-295 | Yüksek7,4 | — | %1,8 | 16 Haz 2019 |
30İzleyin | CVE-2022-21712İstismar yok | Cookie and header exposure in twistedtwisted · twisted · CWE-200 | Yüksek7,5 | — | %1,4 | 7 Şub 2022 |
30İzleyin | CVE-2026-42304İstismar yok | Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chainstwisted · twisted · CWE-400 | Yüksek7,5 | — | %1,0 | 13 May 2026 |
25İzleyin | CVE-2019-12387İstismar yok | In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters stwisted · twisted · CWE-74 | Orta6,1 | — | %2,5 | 10 Haz 2019 |
24İzleyin | CVE-2024-41810Kavram kanıtı | HTML injection in HTTP redirect bodytwisted · twisted · CWE-79 | Orta6,1 | — | %1,2 | 29 Tem 2024 |
22İzleyin | CVE-2016-1000111İstismar yok | Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicationtwisted · twisted · CWE-425 | Orta5,3 | — | %2,8 | 11 Mar 2020 |
21İzleyin | CVE-2022-39348İstismar yok | Twisted vulnerable to NameVirtualHost Host header injectiontwisted · twisted · CWE-79 | Orta5,4 | — | %1,2 | 26 Eki 2022 |
21İzleyin | CVE-2023-46137İstismar yok | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | Orta5,3 | — | %0,8 | 25 Eki 2023 |
- CVE-2020-1010840Planlayın
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4twisted · twisted12 Mar 2020
- CVE-2020-1010940Planlayın
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
KritikCVSS 9,8İstismar yokEPSS %3twisted · twisted12 Mar 2020
- CVE-2022-2480133İzleyin
HTTP Request Smuggling in twisted.web
YüksekCVSS 8,1İstismar yokEPSS %3twisted · twisted4 Nis 2022
- CVE-2024-4167133İzleyin
twisted.web has disordered HTTP pipeline response
YüksekCVSS 8,3İstismar yokEPSS %1twisted · twisted29 Tem 2024
- CVE-2022-2171631İzleyin
Buffer Overflow in Twisted
YüksekCVSS 7,5İstismar yokEPSS %4twisted · twisted3 Mar 2022
- CVE-2014-714331İzleyin
Python Twisted 14.0 trustRoot is not respected in HTTP client
YüksekCVSS 7,5İstismar yokEPSS %3twisted · twisted12 Kas 2019
- CVE-2019-1285530İzleyin
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an atta
YüksekCVSS 7,4İstismar yokEPSS %2twisted · twisted16 Haz 2019
- CVE-2022-2171230İzleyin
Cookie and header exposure in twisted
YüksekCVSS 7,5İstismar yokEPSS %1twisted · twisted7 Şub 2022
- CVE-2026-4230430İzleyin
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
YüksekCVSS 7,5İstismar yokEPSS %1twisted · twisted13 May 2026
- CVE-2019-1238725İzleyin
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters s
OrtaCVSS 6,1İstismar yokEPSS %3twisted · twisted10 Haz 2019
- CVE-2024-4181024İzleyin
HTML injection in HTTP redirect body
OrtaCVSS 6,1Kavram kanıtıEPSS %1twisted · twisted29 Tem 2024
- CVE-2016-100011122İzleyin
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI application
OrtaCVSS 5,3İstismar yokEPSS %3twisted · twisted11 Mar 2020
- CVE-2022-3934821İzleyin
Twisted vulnerable to NameVirtualHost Host header injection
OrtaCVSS 5,4İstismar yokEPSS %1twisted · twisted26 Eki 2022
- CVE-2023-4613721İzleyin
twisted.web has disordered HTTP pipeline response
OrtaCVSS 5,3İstismar yokEPSS %1twisted · twisted25 Eki 2023