CVE Vulnerabilities

CVE-2014-3146

Published: May 14, 2014 | Modified: Dec 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

Affected Software

Name Vendor Start Version End Version
Lxml Lxml * 3.3.4 (including)
Lxml Lxml 0.5 (including) 0.5 (including)
Lxml Lxml 0.5.1 (including) 0.5.1 (including)
Lxml Lxml 0.6 (including) 0.6 (including)
Lxml Lxml 0.7 (including) 0.7 (including)
Lxml Lxml 0.8 (including) 0.8 (including)
Lxml Lxml 0.9 (including) 0.9 (including)
Lxml Lxml 0.9.1 (including) 0.9.1 (including)
Lxml Lxml 0.9.2 (including) 0.9.2 (including)
Lxml Lxml 1.0 (including) 1.0 (including)
Lxml Lxml 1.0.1 (including) 1.0.1 (including)
Lxml Lxml 1.0.2 (including) 1.0.2 (including)
Lxml Lxml 1.0.3 (including) 1.0.3 (including)
Lxml Lxml 1.0.4 (including) 1.0.4 (including)
Lxml Lxml 1.1 (including) 1.1 (including)
Lxml Lxml 1.1.1 (including) 1.1.1 (including)
Lxml Lxml 1.1.2 (including) 1.1.2 (including)
Lxml Lxml 1.2 (including) 1.2 (including)
Lxml Lxml 1.2.1 (including) 1.2.1 (including)
Lxml Lxml 1.3 (including) 1.3 (including)
Lxml Lxml 1.3.1 (including) 1.3.1 (including)
Lxml Lxml 1.3.2 (including) 1.3.2 (including)
Lxml Lxml 1.3.3 (including) 1.3.3 (including)
Lxml Lxml 1.3.4 (including) 1.3.4 (including)
Lxml Lxml 1.3.5 (including) 1.3.5 (including)
Lxml Lxml 1.3.6 (including) 1.3.6 (including)
Lxml Lxml 2.0 (including) 2.0 (including)
Lxml Lxml 2.0.1 (including) 2.0.1 (including)
Lxml Lxml 2.0.2 (including) 2.0.2 (including)
Lxml Lxml 2.0.3 (including) 2.0.3 (including)
Lxml Lxml 2.0.4 (including) 2.0.4 (including)
Lxml Lxml 2.0.5 (including) 2.0.5 (including)
Lxml Lxml 2.0.6 (including) 2.0.6 (including)
Lxml Lxml 2.0.7 (including) 2.0.7 (including)
Lxml Lxml 2.0.8 (including) 2.0.8 (including)
Lxml Lxml 2.0.9 (including) 2.0.9 (including)
Lxml Lxml 2.0.10 (including) 2.0.10 (including)
Lxml Lxml 2.0.11 (including) 2.0.11 (including)
Lxml Lxml 2.1-alpha1 (including) 2.1-alpha1 (including)
Lxml Lxml 2.1-beta1 (including) 2.1-beta1 (including)
Lxml Lxml 2.1-beta2 (including) 2.1-beta2 (including)
Lxml Lxml 2.1-beta3 (including) 2.1-beta3 (including)
Lxml Lxml 2.1.1 (including) 2.1.1 (including)
Lxml Lxml 2.1.2 (including) 2.1.2 (including)
Lxml Lxml 2.1.3 (including) 2.1.3 (including)
Lxml Lxml 2.1.4 (including) 2.1.4 (including)
Lxml Lxml 2.2 (including) 2.2 (including)
Lxml Lxml 2.2-alpha1 (including) 2.2-alpha1 (including)
Lxml Lxml 2.2-beta1 (including) 2.2-beta1 (including)
Lxml Lxml 2.2-beta2 (including) 2.2-beta2 (including)
Lxml Lxml 2.2-beta3 (including) 2.2-beta3 (including)
Lxml Lxml 2.2-beta4 (including) 2.2-beta4 (including)
Lxml Lxml 2.2.1 (including) 2.2.1 (including)
Lxml Lxml 2.2.2 (including) 2.2.2 (including)
Lxml Lxml 2.2.3 (including) 2.2.3 (including)
Lxml Lxml 2.2.4 (including) 2.2.4 (including)
Lxml Lxml 2.2.5 (including) 2.2.5 (including)
Lxml Lxml 2.2.6 (including) 2.2.6 (including)
Lxml Lxml 2.2.7 (including) 2.2.7 (including)
Lxml Lxml 2.2.8 (including) 2.2.8 (including)
Lxml Lxml 2.3 (including) 2.3 (including)
Lxml Lxml 2.3-alpha1 (including) 2.3-alpha1 (including)
Lxml Lxml 2.3-alpha2 (including) 2.3-alpha2 (including)
Lxml Lxml 2.3-beta1 (including) 2.3-beta1 (including)
Lxml Lxml 2.3.1 (including) 2.3.1 (including)
Lxml Lxml 2.3.2 (including) 2.3.2 (including)
Lxml Lxml 2.3.3 (including) 2.3.3 (including)
Lxml Lxml 2.3.4 (including) 2.3.4 (including)
Lxml Lxml 2.3.5 (including) 2.3.5 (including)
Lxml Lxml 2.3.6 (including) 2.3.6 (including)
Lxml Lxml 3.0 (including) 3.0 (including)
Lxml Lxml 3.0-alpha1 (including) 3.0-alpha1 (including)
Lxml Lxml 3.0-alpha2 (including) 3.0-alpha2 (including)
Lxml Lxml 3.0-beta1 (including) 3.0-beta1 (including)
Lxml Lxml 3.0.1 (including) 3.0.1 (including)
Lxml Lxml 3.0.2 (including) 3.0.2 (including)
Lxml Lxml 3.1-beta1 (including) 3.1-beta1 (including)
Lxml Lxml 3.1.0 (including) 3.1.0 (including)
Lxml Lxml 3.1.1 (including) 3.1.1 (including)
Lxml Lxml 3.1.2 (including) 3.1.2 (including)
Lxml Lxml 3.2.0 (including) 3.2.0 (including)
Lxml Lxml 3.2.1 (including) 3.2.1 (including)
Lxml Lxml 3.2.2 (including) 3.2.2 (including)
Lxml Lxml 3.2.3 (including) 3.2.3 (including)
Lxml Lxml 3.2.4 (including) 3.2.4 (including)
Lxml Lxml 3.2.5 (including) 3.2.5 (including)
Lxml Lxml 3.3.0 (including) 3.3.0 (including)
Lxml Lxml 3.3.0-beta1 (including) 3.3.0-beta1 (including)
Lxml Lxml 3.3.0-beta2 (including) 3.3.0-beta2 (including)
Lxml Lxml 3.3.0-beta3 (including) 3.3.0-beta3 (including)
Lxml Lxml 3.3.0-beta4 (including) 3.3.0-beta4 (including)
Lxml Lxml 3.3.0-beta5 (including) 3.3.0-beta5 (including)
Lxml Lxml 3.3.1 (including) 3.3.1 (including)
Lxml Lxml 3.3.2 (including) 3.3.2 (including)
Lxml Lxml 3.3.3 (including) 3.3.3 (including)
Lxml Ubuntu lucid *
Lxml Ubuntu precise *
Lxml Ubuntu quantal *
Lxml Ubuntu saucy *
Lxml Ubuntu trusty *
Lxml Ubuntu upstream *

References