Skip to main content

Vendor archive

djangoproject CVEs

Beta · best-effort

158 CVEs tagged to vendor djangoproject13 Critical, 49 High, 82 Medium, 14 Low, 0 Unrated.

CVE-2011-4103

Published Oct 27, 2014

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0483

Published Aug 26, 2014

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represen…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0482

Published Aug 26, 2014

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the con…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0480

Published Aug 26, 2014

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1418

Published May 16, 2014

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0472

Published Apr 23, 2014

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and ex…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6044

Published Oct 4, 2013

The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4249

Published Oct 4, 2013

Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1443

Published Sep 23, 2013

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of servi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4315

Published Sep 16, 2013

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4520

Published Nov 18, 2012

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted userna…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3444

Published Jul 31, 2012

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3443

Published Jul 31, 2012

The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3442

Published Jul 31, 2012

The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4140

Published Oct 19, 2011

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4139

Published Oct 19, 2011

Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poiso…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4138

Published Oct 19, 2011

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then use…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4137

Published Oct 19, 2011

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL wit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4136

Published Oct 19, 2011

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and applicati…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 158 CVEsPage 6 of 7