Записи twisted
14 опубликованных записей вендора twisted.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-295 Improper Certificate Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-425 Direct Request ('Forced Browsing')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-10108Эксплойта нет | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Критическая9,8 | — | 4,0 % | 12 мар. 2020 г. |
40В плане | CVE-2020-10109Эксплойта нет | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Критическая9,8 | — | 3,3 % | 12 мар. 2020 г. |
33Наблюдать | CVE-2022-24801Эксплойта нет | HTTP Request Smuggling in twisted.webtwisted · twisted · CWE-444 | Высокая8,1 | — | 2,8 % | 4 апр. 2022 г. |
33Наблюдать | CVE-2024-41671Эксплойта нет | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | Высокая8,3 | — | 0,9 % | 29 июл. 2024 г. |
31Наблюдать | CVE-2022-21716Эксплойта нет | Buffer Overflow in Twistedtwisted · twisted · CWE-120 | Высокая7,5 | — | 3,5 % | 3 мар. 2022 г. |
31Наблюдать | CVE-2014-7143Эксплойта нет | Python Twisted 14.0 trustRoot is not respected in HTTP clienttwisted · twisted · CWE-295 | Высокая7,5 | — | 2,6 % | 12 нояб. 2019 г. |
30Наблюдать | CVE-2019-12855Эксплойта нет | In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attatwisted · twisted · CWE-295 | Высокая7,4 | — | 1,8 % | 16 июн. 2019 г. |
30Наблюдать | CVE-2022-21712Эксплойта нет | Cookie and header exposure in twistedtwisted · twisted · CWE-200 | Высокая7,5 | — | 1,4 % | 7 февр. 2022 г. |
30Наблюдать | CVE-2026-42304Эксплойта нет | Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chainstwisted · twisted · CWE-400 | Высокая7,5 | — | 1,0 % | 13 мая 2026 г. |
25Наблюдать | CVE-2019-12387Эксплойта нет | In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters stwisted · twisted · CWE-74 | Средняя6,1 | — | 2,5 % | 10 июн. 2019 г. |
24Наблюдать | CVE-2024-41810Proof of concept | HTML injection in HTTP redirect bodytwisted · twisted · CWE-79 | Средняя6,1 | — | 1,2 % | 29 июл. 2024 г. |
22Наблюдать | CVE-2016-1000111Эксплойта нет | Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicationtwisted · twisted · CWE-425 | Средняя5,3 | — | 2,8 % | 11 мар. 2020 г. |
21Наблюдать | CVE-2022-39348Эксплойта нет | Twisted vulnerable to NameVirtualHost Host header injectiontwisted · twisted · CWE-79 | Средняя5,4 | — | 1,2 % | 26 окт. 2022 г. |
21Наблюдать | CVE-2023-46137Эксплойта нет | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | Средняя5,3 | — | 0,8 % | 25 окт. 2023 г. |
- CVE-2020-1010840В плане
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %twisted · twisted12 мар. 2020 г.
- CVE-2020-1010940В плане
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %twisted · twisted12 мар. 2020 г.
- CVE-2022-2480133Наблюдать
HTTP Request Smuggling in twisted.web
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %twisted · twisted4 апр. 2022 г.
- CVE-2024-4167133Наблюдать
twisted.web has disordered HTTP pipeline response
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %twisted · twisted29 июл. 2024 г.
- CVE-2022-2171631Наблюдать
Buffer Overflow in Twisted
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %twisted · twisted3 мар. 2022 г.
- CVE-2014-714331Наблюдать
Python Twisted 14.0 trustRoot is not respected in HTTP client
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %twisted · twisted12 нояб. 2019 г.
- CVE-2019-1285530Наблюдать
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an atta
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %twisted · twisted16 июн. 2019 г.
- CVE-2022-2171230Наблюдать
Cookie and header exposure in twisted
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %twisted · twisted7 февр. 2022 г.
- CVE-2026-4230430Наблюдать
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %twisted · twisted13 мая 2026 г.
- CVE-2019-1238725Наблюдать
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters s
СредняяCVSS 6,1Эксплойта нетEPSS 3 %twisted · twisted10 июн. 2019 г.
- CVE-2024-4181024Наблюдать
HTML injection in HTTP redirect body
СредняяCVSS 6,1Proof of conceptEPSS 1 %twisted · twisted29 июл. 2024 г.
- CVE-2016-100011122Наблюдать
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI application
СредняяCVSS 5,3Эксплойта нетEPSS 3 %twisted · twisted11 мар. 2020 г.
- CVE-2022-3934821Наблюдать
Twisted vulnerable to NameVirtualHost Host header injection
СредняяCVSS 5,4Эксплойта нетEPSS 1 %twisted · twisted26 окт. 2022 г.
- CVE-2023-4613721Наблюдать
twisted.web has disordered HTTP pipeline response
СредняяCVSS 5,3Эксплойта нетEPSS 1 %twisted · twisted25 окт. 2023 г.