VYPR
Vendor
Products
1
CVEs
2
Across products
27
Status
Private

Products

1

Recent CVEs

2
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-9964Med0.356.50.01Dec 16, 2016redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
CVE-2014-31370.000.01Oct 25, 2014Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.