Lucene search

K
cveDebianCVE-2014-0474
HistoryApr 23, 2014 - 3:55 p.m.

CVE-2014-0474

2014-04-2315:55:03
CWE-399
debian
web.nvd.nist.gov
69
cve-2014-0474
django
type conversion
remote attackers
nvd
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.017

Percentile

87.7%

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to “MySQL typecasting.”

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch10.04-lts
OR
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.10
OR
canonicalubuntu_linuxMatch14.04lts
Node
djangoprojectdjangoMatch1.6
OR
djangoprojectdjangoMatch1.6.1
OR
djangoprojectdjangoMatch1.6.2
Node
djangoprojectdjangoRange1.4.10
OR
djangoprojectdjangoMatch1.4
OR
djangoprojectdjangoMatch1.4.1
OR
djangoprojectdjangoMatch1.4.2
OR
djangoprojectdjangoMatch1.4.3
OR
djangoprojectdjangoMatch1.4.4
OR
djangoprojectdjangoMatch1.4.5
OR
djangoprojectdjangoMatch1.4.6
OR
djangoprojectdjangoMatch1.4.7
OR
djangoprojectdjangoMatch1.4.8
OR
djangoprojectdjangoMatch1.4.9
Node
djangoprojectdjangoMatch1.7alpha1
OR
djangoprojectdjangoMatch1.7alpha2
OR
djangoprojectdjangoMatch1.7beta1
Node
djangoprojectdjangoMatch1.5
OR
djangoprojectdjangoMatch1.5.1
OR
djangoprojectdjangoMatch1.5.2
OR
djangoprojectdjangoMatch1.5.3
OR
djangoprojectdjangoMatch1.5.4
OR
djangoprojectdjangoMatch1.5.5
VendorProductVersionCPE
canonicalubuntu_linux10.04cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
canonicalubuntu_linux12.10cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
canonicalubuntu_linux13.10cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
canonicalubuntu_linux14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
djangoprojectdjango1.6cpe:2.3:a:djangoproject:django:1.6:*:*:*:*:*:*:*
djangoprojectdjango1.6.1cpe:2.3:a:djangoproject:django:1.6.1:*:*:*:*:*:*:*
djangoprojectdjango1.6.2cpe:2.3:a:djangoproject:django:1.6.2:*:*:*:*:*:*:*
djangoprojectdjango*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
djangoprojectdjango1.4cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.017

Percentile

87.7%