Total vulnerabilities in the database
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Software | From | Fixed in |
---|---|---|
lxml / lxml | 1.2 | 4.6.2 |
redhat / enterprise_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
oracle / communications_offline_mediation_controller | 12.0.0.3.0 | 12.0.0.3.0.x |
oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
![]() |
- | 4.6.2 |