Products: 1
Vulnerabilities: 4
Known Exploited: 0
1
Critical Level Threats
0
High Level Threats
3
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Last Modified: Nov 21, 2024
Published: May 29, 2022
CVE-2020-28473
Web Cache Poisoning
Last Modified: Nov 21, 2024
Published: Jan 18, 2021
CVE-2016-9964
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
Last Modified: Apr 12, 2025
Published: Dec 16, 2016
CVE-2014-3137
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
Last Modified: Apr 12, 2025
Published: Oct 25, 2014
Items Per Page
