4.3

CVE-2014-3146

Exploit
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lxml ≫ Lxml Version <= 3.3.4
Lxml ≫ Lxml Version 0.5
Lxml ≫ Lxml Version 0.5.1
Lxml ≫ Lxml Version 0.6
Lxml ≫ Lxml Version 0.7
Lxml ≫ Lxml Version 0.8
Lxml ≫ Lxml Version 0.9
Lxml ≫ Lxml Version 0.9.1
Lxml ≫ Lxml Version 0.9.2
Lxml ≫ Lxml Version 1.0
Lxml ≫ Lxml Version 1.0.1
Lxml ≫ Lxml Version 1.0.2
Lxml ≫ Lxml Version 1.0.3
Lxml ≫ Lxml Version 1.0.4
Lxml ≫ Lxml Version 1.1
Lxml ≫ Lxml Version 1.1.1
Lxml ≫ Lxml Version 1.1.2
Lxml ≫ Lxml Version 1.2
Lxml ≫ Lxml Version 1.2.1
Lxml ≫ Lxml Version 1.3
Lxml ≫ Lxml Version 1.3.1
Lxml ≫ Lxml Version 1.3.2
Lxml ≫ Lxml Version 1.3.3
Lxml ≫ Lxml Version 1.3.4
Lxml ≫ Lxml Version 1.3.5
Lxml ≫ Lxml Version 1.3.6
Lxml ≫ Lxml Version 2.0
Lxml ≫ Lxml Version 2.0.1
Lxml ≫ Lxml Version 2.0.2
Lxml ≫ Lxml Version 2.0.3
Lxml ≫ Lxml Version 2.0.4
Lxml ≫ Lxml Version 2.0.5
Lxml ≫ Lxml Version 2.0.6
Lxml ≫ Lxml Version 2.0.7
Lxml ≫ Lxml Version 2.0.8
Lxml ≫ Lxml Version 2.0.9
Lxml ≫ Lxml Version 2.0.10
Lxml ≫ Lxml Version 2.0.11
Lxml ≫ Lxml Version 2.1 Update alpha1
Lxml ≫ Lxml Version 2.1 Update beta1
Lxml ≫ Lxml Version 2.1 Update beta2
Lxml ≫ Lxml Version 2.1 Update beta3
Lxml ≫ Lxml Version 2.1.1
Lxml ≫ Lxml Version 2.1.2
Lxml ≫ Lxml Version 2.1.3
Lxml ≫ Lxml Version 2.1.4
Lxml ≫ Lxml Version 2.2 Update -
Lxml ≫ Lxml Version 2.2 Update alpha1
Lxml ≫ Lxml Version 2.2 Update beta1
Lxml ≫ Lxml Version 2.2 Update beta2
Lxml ≫ Lxml Version 2.2 Update beta3
Lxml ≫ Lxml Version 2.2 Update beta4
Lxml ≫ Lxml Version 2.2.1
Lxml ≫ Lxml Version 2.2.2
Lxml ≫ Lxml Version 2.2.3
Lxml ≫ Lxml Version 2.2.4
Lxml ≫ Lxml Version 2.2.5
Lxml ≫ Lxml Version 2.2.6
Lxml ≫ Lxml Version 2.2.7
Lxml ≫ Lxml Version 2.2.8
Lxml ≫ Lxml Version 2.3 Update -
Lxml ≫ Lxml Version 2.3 Update alpha1
Lxml ≫ Lxml Version 2.3 Update alpha2
Lxml ≫ Lxml Version 2.3 Update beta1
Lxml ≫ Lxml Version 2.3.1
Lxml ≫ Lxml Version 2.3.2
Lxml ≫ Lxml Version 2.3.3
Lxml ≫ Lxml Version 2.3.4
Lxml ≫ Lxml Version 2.3.5
Lxml ≫ Lxml Version 2.3.6
Lxml ≫ Lxml Version 3.0 Update -
Lxml ≫ Lxml Version 3.0 Update alpha1
Lxml ≫ Lxml Version 3.0 Update alpha2
Lxml ≫ Lxml Version 3.0 Update beta1
Lxml ≫ Lxml Version 3.0.1
Lxml ≫ Lxml Version 3.0.2
Lxml ≫ Lxml Version 3.1 Update beta1
Lxml ≫ Lxml Version 3.1.0
Lxml ≫ Lxml Version 3.1.1
Lxml ≫ Lxml Version 3.1.2
Lxml ≫ Lxml Version 3.2.0
Lxml ≫ Lxml Version 3.2.1
Lxml ≫ Lxml Version 3.2.2
Lxml ≫ Lxml Version 3.2.3
Lxml ≫ Lxml Version 3.2.4
Lxml ≫ Lxml Version 3.2.5
Lxml ≫ Lxml Version 3.3.0 Update -
Lxml ≫ Lxml Version 3.3.0 Update beta1
Lxml ≫ Lxml Version 3.3.0 Update beta2
Lxml ≫ Lxml Version 3.3.0 Update beta3
Lxml ≫ Lxml Version 3.3.0 Update beta4
Lxml ≫ Lxml Version 3.3.0 Update beta5
Lxml ≫ Lxml Version 3.3.1
Lxml ≫ Lxml Version 3.3.2
Lxml ≫ Lxml Version 3.3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.33% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://advisories.mageia.org/MGASA-2014-0218.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00083.html
http://lxml.de/3.3/changes-3.3.5.html
http://seclists.org/fulldisclosure/2014/Apr/210
http://seclists.org/fulldisclosure/2014/Apr/319
Exploit
http://secunia.com/advisories/58013
Vendor Advisory
http://secunia.com/advisories/58744
http://secunia.com/advisories/59008
http://www.debian.org/security/2014/dsa-2941
http://www.mandriva.com/security/advisories?name=MDVSA-2015:112
http://www.openwall.com/lists/oss-security/2014/05/09/7
http://www.securityfocus.com/bid/67159
Exploit
http://www.ubuntu.com/usn/USN-2217-1
https://mailman-mail5.webfaction.com/pipermail/lxml/2014-April/007128.html
Exploit