ipython kayıtları
ipython üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation2
- CWE-250 Execution with Unnecessary Privileges1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2015-5607İstismar yok | Cross-site request forgery in the REST API in IPython 2 and 3.ipython · ipython · CWE-352 | Yüksek8,8 | — | %1,2 | 20 Eyl 2017 |
35İzleyin | CVE-2022-21699İstismar yok | Execution with Unnecessary Privileges in ipythonipython · ipython · CWE-250 | Yüksek8,8 | — | %0,7 | 19 Oca 2022 |
28İzleyin | CVE-2014-3429İstismar yok | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute aripython · ipython notebook · CWE-94 | Orta6,8 | — | %4,7 | 7 Ağu 2014 |
28İzleyin | CVE-2015-7337İstismar yok | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript ipython · notebook · CWE-20 | Orta6,8 | — | %2,5 | 29 Eyl 2015 |
28İzleyin | CVE-2023-24816İstismar yok | set_term_title command injection in ipythonipython · ipython · CWE-20 | Yüksek7,0 | — | %1,3 | 10 Şub 2023 |
25İzleyin | CVE-2015-4707İstismar yok | Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors inipython · ipython · CWE-79 | Orta6,1 | — | %2,3 | 20 Eyl 2017 |
25İzleyin | CVE-2015-4706İstismar yok | Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectoripython · ipython · CWE-79 | Orta6,1 | — | %2,1 | 21 Eyl 2017 |
18İzleyin | CVE-2015-6938İstismar yok | Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Noteboojupyter · notebook · CWE-79 | Orta4,3 | — | %2,8 | 21 Eyl 2015 |
- CVE-2015-560735İzleyin
Cross-site request forgery in the REST API in IPython 2 and 3.
YüksekCVSS 8,8İstismar yokEPSS %1ipython · ipython20 Eyl 2017
- CVE-2022-2169935İzleyin
Execution with Unnecessary Privileges in ipython
YüksekCVSS 8,8İstismar yokEPSS %1ipython · ipython19 Oca 2022
- CVE-2014-342928İzleyin
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute ar
OrtaCVSS 6,8İstismar yokEPSS %5ipython · ipython notebook7 Ağu 2014
- CVE-2015-733728İzleyin
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript
OrtaCVSS 6,8İstismar yokEPSS %2ipython · notebook29 Eyl 2015
- CVE-2023-2481628İzleyin
set_term_title command injection in ipython
YüksekCVSS 7,0İstismar yokEPSS %1ipython · ipython10 Şub 2023
- CVE-2015-470725İzleyin
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors in
OrtaCVSS 6,1İstismar yokEPSS %2ipython · ipython20 Eyl 2017
- CVE-2015-470625İzleyin
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vector
OrtaCVSS 6,1İstismar yokEPSS %2ipython · ipython21 Eyl 2017
- CVE-2015-693818İzleyin
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Noteboo
OrtaCVSS 4,3İstismar yokEPSS %3jupyter · notebook21 Eyl 2015