446
VMScore

CVE-2019-1010083

Published: 17/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Pallets Project Flask prior to 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

palletsprojects flask

Github Repositories

pip-audit pip-audit is a tool for scanning Python environments for packages with known vulnerabilities It uses the Python Packaging Advisory Database (githubcom/pypa/advisory-database) via the PyPI JSON API as a source of vulnerability reports This project is maintained in part by Trail of Bits with support from Google This is not an official Google or Trail o

Pulsecheck - Get current and historical vulnerability insights from the GItHub Advisory Database https://github.com/advisories/database, by checking the pulse of your project’s dependencies delivered in an easy-to-use CLI.

Pulsecheck I wrote Pulsecheck to serve as a tool for early-stage research on OSS third-party libraries and package vulnerabilities Pulsecheck parses your dependency files and queries the GitHub Advisory Database for all relevant GitHub-reviewed security advisories It will provide data on every reviewed GHSA advisory for your respective dependency This project showcases how t

Audits Python environments and dependency trees for known vulnerabilities

pip-audit pip-audit is a tool for scanning Python environments for packages with known vulnerabilities It uses the Python Packaging Advisory Database (githubcom/pypa/advisory-database) via the PyPI JSON API as a source of vulnerability reports This project is maintained in part by Trail of Bits with support from Google This is not an official Google or Trail o

Audits Python environments and dependency trees for known vulnerabilities

pip-audit pip-audit is a tool for scanning Python environments for packages with known vulnerabilities It uses the Python Packaging Advisory Database (githubcom/pypa/advisory-database) via the PyPI JSON API as a source of vulnerability reports This project is maintained in part by Trail of Bits with support from Google This is not an official Google or Trail o