VYPR

rpm package

suse/python-Django&distro=SUSE Enterprise Storage 1.0

pkg:rpm/suse/python-Django&distro=SUSE%20Enterprise%20Storage%201.0

Vulnerabilities (9)

  • CVE-2015-8213Dec 7, 2015
    affected < 1.6.11-11.1fixed 1.6.11-11.1

    The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_

  • CVE-2015-5963Aug 24, 2015
    affected < 1.6.11-8.1fixed 1.6.11-8.1

    contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of reque

  • CVE-2015-5144Jul 14, 2015
    affected < 1.6.11-8.1fixed 1.6.11-8.1

    Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the

  • CVE-2015-5143Jul 14, 2015
    affected < 1.6.11-8.1fixed 1.6.11-8.1

    The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.

  • CVE-2015-2317Mar 25, 2015
    affected < 1.6.11-4.1fixed 1.6.11-4.1

    The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as de

  • CVE-2015-2316Mar 25, 2015
    affected < 1.6.11-4.1fixed 1.6.11-4.1

    The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

  • CVE-2015-0222Jan 16, 2015
    affected < 1.6.11-4.1fixed 1.6.11-4.1

    ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

  • CVE-2015-0221Jan 16, 2015
    affected < 1.6.11-4.1fixed 1.6.11-4.1

    The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

  • CVE-2015-0219Jan 16, 2015
    affected < 1.6.11-4.1fixed 1.6.11-4.1

    Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.