Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-0481

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

  • Published: Aug 26, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-0481
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
opensuse_project / opensuse 12.3 12.3.x
opensuse / opensuse 13.1 13.1.x
djangoproject / django 1.4.12 1.4.12.x
djangoproject / django 1.4.9 1.4.9.x
djangoproject / django 1.4.10 1.4.10.x
djangoproject / django 1.4.6 1.4.6.x
djangoproject / django 1.4.4 1.4.4.x
djangoproject / django 1.4.5 1.4.5.x
djangoproject / django 1.4.2 1.4.2.x
djangoproject / django 1.4.11 1.4.11.x
djangoproject / django 1.4.7 1.4.7.x
djangoproject / django 1.4.8 1.4.8.x
djangoproject / django 1.4 1.4.x
djangoproject / django - 1.4.13.x
djangoproject / django 1.4.1 1.4.1.x
djangoproject / django 1.5 1.5.x
djangoproject / django 1.5.7 1.5.7.x
djangoproject / django 1.5.1 1.5.1.x
djangoproject / django 1.5.3 1.5.3.x
djangoproject / django 1.5.4 1.5.4.x
djangoproject / django 1.5-beta 1.5-beta.x
djangoproject / django 1.5.5 1.5.5.x
djangoproject / django 1.5.8 1.5.8.x
djangoproject / django 1.5.2 1.5.2.x
djangoproject / django 1.5-alpha 1.5-alpha.x
djangoproject / django 1.5.6 1.5.6.x
djangoproject / django 1.7-rc2 1.7-rc2.x
djangoproject / django 1.7-beta1 1.7-beta1.x
djangoproject / django 1.7-beta3 1.7-beta3.x
djangoproject / django 1.7-rc1 1.7-rc1.x
djangoproject / django 1.7-beta2 1.7-beta2.x
djangoproject / django 1.7-beta4 1.7-beta4.x
djangoproject / django 1.6-beta4 1.6-beta4.x
djangoproject / django 1.6.5 1.6.5.x
djangoproject / django 1.6-beta2 1.6-beta2.x
djangoproject / django 1.6.3 1.6.3.x
djangoproject / django 1.6.4 1.6.4.x
djangoproject / django 1.6 1.6.x
djangoproject / django 1.6.1 1.6.1.x
djangoproject / django 1.6.2 1.6.2.x
djangoproject / django 1.6-beta1 1.6-beta1.x
djangoproject / django 1.6-beta3 1.6-beta3.x
debian / debian_linux 7.0 7.0.x