Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
djangoproject django 1.3 vulnerabilities and exploits
(subscribe to this query)
570
VMScore
CVE-2012-4520
The django.http.HttpRequest.get_host function in Django 1.3.x prior to 1.3.4 and 1.4.x prior to 1.4.2 allows remote malicious users to generate and display arbitrary URLs via crafted username and password Host header values.
Djangoproject Django 1.3.2
Djangoproject Django 1.3.3
Djangoproject Django 1.3
Djangoproject Django 1.3.1
Djangoproject Django 1.4
Djangoproject Django 1.4.1
445
VMScore
CVE-2010-4535
The password reset functionality in django.contrib.auth in Django prior to 1.1.3, 1.2.x prior to 1.2.4, and 1.3.x prior to 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote malicious users to cause a denial of service (resour...
Djangoproject Django 1.0
Djangoproject Django 1.0.1
Djangoproject Django 1.0.2
Djangoproject Django 0.95.1
Djangoproject Django 0.96
Djangoproject Django 1.1
Djangoproject Django
Djangoproject Django 0.91
Djangoproject Django 0.95
Djangoproject Django 1.1.0
Djangoproject Django 1.2.3
Djangoproject Django 1.2
Djangoproject Django 1.2.1
Djangoproject Django 1.2.2
Djangoproject Django 1.3
356
VMScore
CVE-2010-4534
The administrative interface in django.contrib.admin in Django prior to 1.1.3, 1.2.x prior to 1.2.4, and 1.3.x prior to 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive i...
Djangoproject Django 0.95.1
Djangoproject Django 0.96
Djangoproject Django 0.91
Djangoproject Django 0.95
Djangoproject Django
Djangoproject Django 1.1.0
Djangoproject Django 1.0
Djangoproject Django 1.0.1
Djangoproject Django 1.0.2
Djangoproject Django 1.1
Djangoproject Django 1.2.1
Djangoproject Django 1.2.2
Djangoproject Django 1.2.3
Djangoproject Django 1.2
Djangoproject Django 1.3
383
VMScore
CVE-2012-3442
The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django prior to 1.3.2 and 1.4.x prior to 1.4.1 do not validate the scheme of a redirect target, which might allow remote malicious users to conduct cross-site scripting (XSS) att...
Djangoproject Django 1.2
Djangoproject Django 1.2-alpha1
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.3
Djangoproject Django 1.2.2
Djangoproject Django 0.95
Djangoproject Django 1.4
Djangoproject Django 1.2.7
Djangoproject Django 1.2.6
Djangoproject Django 1.1.4
Djangoproject Django 1.0.2
Djangoproject Django
Djangoproject Django 1.2.5
Djangoproject Django 1.2.4
Djangoproject Django 1.1.3
Djangoproject Django 1.1.2
Djangoproject Django 1.0.1
Djangoproject Django 0.96
445
VMScore
CVE-2012-3443
The django.forms.ImageField class in the form system in Django prior to 1.3.2 and 1.4.x prior to 1.4.1 completely decompresses image data during image validation, which allows remote malicious users to cause a denial of service (memory consumption) by uploading an image file.
Djangoproject Django
Djangoproject Django 1.3
Djangoproject Django 1.2.6
Djangoproject Django 1.2.5
Djangoproject Django 1.1.4
Djangoproject Django 1.1.3
Djangoproject Django 1.0.1
Djangoproject Django 0.96
Djangoproject Django 1.2
Djangoproject Django 1.2.7
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.0.2
Djangoproject Django 1.2.4
Djangoproject Django 1.2.2
Djangoproject Django 1.1.2
Djangoproject Django 0.95
Djangoproject Django 1.4
Djangoproject Django 1.2-alpha1
445
VMScore
CVE-2012-3444
The get_image_dimensions function in the image-handling functionality in Django prior to 1.3.2 and 1.4.x prior to 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote malicious users to cause a denial of service (process or thread consumpt...
Djangoproject Django 1.2
Djangoproject Django 1.2.2
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.4
Djangoproject Django 1.3
Djangoproject Django 1.2.5
Djangoproject Django 1.2.4
Djangoproject Django 1.1.2
Djangoproject Django 0.96
Djangoproject Django 0.95
Djangoproject Django 1.2-alpha1
Djangoproject Django
Djangoproject Django 1.2.7
Djangoproject Django 1.2.6
Djangoproject Django 1.1.4
Djangoproject Django 1.1.3
Djangoproject Django 1.0.2
Djangoproject Django 1.0.1
516
VMScore
CVE-2011-4136
django.contrib.sessions in Django prior to 1.2.7 and 1.3.x prior to 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote malicious users to modify a session by triggering use of a key ...
Djangoproject Django 1.2.1
Djangoproject Django 1.1.2
Djangoproject Django 1.0.2
Djangoproject Django
Djangoproject Django 0.95
Djangoproject Django 0.95.1
Djangoproject Django 1.2.3
Djangoproject Django 1.1.0
Djangoproject Django 1.2.4
Djangoproject Django 1.2.5
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.3
Djangoproject Django 1.2
Djangoproject Django 1.1.3
Djangoproject Django 0.91
Djangoproject Django 1.2.2
Djangoproject Django 1.0.1
Djangoproject Django 0.96
445
VMScore
CVE-2011-4137
The verify_exists functionality in the URLField implementation in Django prior to 1.2.7 and 1.3.x prior to 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote malicious users to cause a denial of service (resource consumpt...
Djangoproject Django 0.91
Djangoproject Django 1.2.2
Djangoproject Django 1.0.1
Djangoproject Django 0.96
Djangoproject Django 1.2.1
Djangoproject Django 1.1.2
Djangoproject Django 1.0.2
Djangoproject Django
Djangoproject Django 0.95
Djangoproject Django 0.95.1
Djangoproject Django 1.2.3
Djangoproject Django 1.1.0
Djangoproject Django 1.2.4
Djangoproject Django 1.2.5
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.3
Djangoproject Django 1.2
Djangoproject Django 1.1.3
445
VMScore
CVE-2011-4138
The verify_exists functionality in the URLField implementation in Django prior to 1.2.7 and 1.3.x prior to 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote m...
Djangoproject Django 0.91
Djangoproject Django 1.2.2
Djangoproject Django 1.0.1
Djangoproject Django 0.96
Djangoproject Django 1.2.1
Djangoproject Django 1.1.2
Djangoproject Django 1.0.2
Djangoproject Django
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.3
Djangoproject Django 1.2
Djangoproject Django 1.1.3
Djangoproject Django 0.95
Djangoproject Django 0.95.1
Djangoproject Django 1.2.3
Djangoproject Django 1.1.0
Djangoproject Django 1.2.4
Djangoproject Django 1.2.5
445
VMScore
CVE-2011-4139
Django prior to 1.2.7 and 1.3.x prior to 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote malicious users to conduct cache poisoning attacks via a crafted request.
Djangoproject Django 1.1
Djangoproject Django 1.0
Djangoproject Django 1.3
Djangoproject Django 1.2
Djangoproject Django 0.91
Djangoproject Django 1.2.2
Djangoproject Django 1.0.1
Djangoproject Django 0.96
Djangoproject Django 0.95
Djangoproject Django 0.95.1
Djangoproject Django 1.2.3
Djangoproject Django 1.1.0
Djangoproject Django 1.1.3
Djangoproject Django 1.2.4
Djangoproject Django 1.2.5
Djangoproject Django 1.2.1
Djangoproject Django 1.1.2
Djangoproject Django 1.0.2
Djangoproject Django
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »