Mark Pilgrim Feedparser vulnerabilities
5 known vulnerabilities affecting mark_pilgrim/feedparser.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2009-5065P4MEDIUMCVSS 4.3PoC≤ 4.1v3.0+7 more2011-04-11
CVE-2009-5065 [MEDIUM] CWE-79 CVE-2009-5065: Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser o
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.
ghsanvdosv
CVE-2012-2921P4MEDIUMCVSS 5.0≤ 5.1.1v3.0+12 more2012-05-21
CVE-2012-2921 [MEDIUM] CWE-399 CVE-2012-2921: Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to
Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.
ghsanvdosv
CVE-2011-1157P4MEDIUMCVSS 4.3v5.02011-04-11
CVE-2011-1157 [MEDIUM] CWE-79 CVE-2011-1157: Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser o
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments.
ghsanvdosv
CVE-2011-1156P4MEDIUMCVSS 5.0≤ 5.0v3.0+8 more2011-04-11
CVE-2011-1156 [MEDIUM] CWE-399 CVE-2011-1156: feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0.1 allows rem
feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0.1 allows remote attackers to cause a denial of service (application crash) via a malformed DOCTYPE declaration.
ghsanvdosv
CVE-2011-1158P4MEDIUMCVSS 4.3v5.02011-04-11
CVE-2011-1158 [MEDIUM] CWE-79 CVE-2011-1158: Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser o
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.
ghsanvdosv