Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
165 changes: 165 additions & 0 deletions advisories/BREW-animdl-CVE-2014-3146.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,165 @@
{
"schema_version": "1.7.3",
"id": "BREW-animdl-CVE-2014-3146",
"published": "2026-08-13T16:35:16Z",
"modified": "2026-08-13T16:35:16Z",
"upstream": [
"GHSA-57qw-cc2g-pv5p",
"CVE-2014-3146",
"PYSEC-2014-9"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "animdl",
"purl": "pkg:brew/animdl"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.7.27_5"
}
]
}
],
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"upstream_fixed_in": "3.3.5",
"resource": "lxml",
"resource_purl": "pkg:pypi/lxml@5.3.1"
}
}
],
"database_specific": {
"source": "matched",
"strategy": "registry",
"confidence": "high",
"upstream_evidence": [
{
"strategy": "registry",
"ecosystem": "PyPI",
"name": "lxml",
"subject_version": "5.3.1",
"key": "pkg:pypi/lxml@5.3.1",
"resource": "lxml"
},
{
"strategy": "registry",
"ecosystem": "PyPI",
"name": "lxml",
"subject_version": "5.3.1",
"key": "pkg:pypi/lxml@5.3.1",
"resource": "lxml"
}
]
},
"summary": "lxml Cross-site Scripting Via Control Characters",
"details": "Incomplete blacklist vulnerability in the `lxml.html.clean` module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the `clean_html` function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3146"
},
{
"type": "WEB",
"url": "https://github.com/lxml/lxml/pull/273"
},
{
"type": "WEB",
"url": "https://github.com/lxml/lxml/commit/3f3082e0a67851cde26a48da3d1f4b75d8aa07ec"
},
{
"type": "WEB",
"url": "https://github.com/lxml/lxml/commit/86e81ab393ba14c1be71284675851a3bdce57d69"
},
{
"type": "WEB",
"url": "https://github.com/lxml/lxml/commit/e86b294f1f81b899a59925123560ff924a72f1cc"
},
{
"type": "PACKAGE",
"url": "https://github.com/lxml/lxml"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/lxml/PYSEC-2014-9.yaml"
},
{
"type": "WEB",
"url": "https://mailman-mail5.webfaction.com/pipermail/lxml/2014-April/007128.html"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20140724172044/http://secunia.com/advisories/58013"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20140805110535/http://secunia.com/advisories/59008"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20140806061046/http://secunia.com/advisories/58744"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20141017122607/https://mailman-mail5.webfaction.com/pipermail/lxml/2014-April/007128.html"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20150523055039/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015:112/?name=MDVSA-2015:112"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200228180542/http://www.securityfocus.com/bid/67159"
},
{
"type": "WEB",
"url": "http://advisories.mageia.org/MGASA-2014-0218.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00083.html"
},
{
"type": "WEB",
"url": "http://lxml.de/3.3/changes-3.3.5.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2014/Apr/210"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2014/Apr/319"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2014/dsa-2941"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2014/05/09/7"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-2217-1"
}
]
}
133 changes: 133 additions & 0 deletions advisories/BREW-animdl-CVE-2015-8557.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,133 @@
{
"schema_version": "1.7.3",
"id": "BREW-animdl-CVE-2015-8557",
"published": "2026-08-13T16:35:16Z",
"modified": "2026-08-13T16:35:16Z",
"upstream": [
"GHSA-fff8-4w9p-7v76",
"CVE-2015-8557",
"PYSEC-2016-32"
],
"affected": [
{
"package": {
"ecosystem": "Homebrew",
"name": "animdl",
"purl": "pkg:brew/animdl"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.7.27_5"
}
]
}
],
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"upstream_fixed_in": "2.1",
"resource": "pygments",
"resource_purl": "pkg:pypi/pygments@2.20.0"
}
}
],
"database_specific": {
"source": "matched",
"strategy": "registry",
"confidence": "high",
"upstream_evidence": [
{
"strategy": "registry",
"ecosystem": "PyPI",
"name": "pygments",
"subject_version": "2.20.0",
"key": "pkg:pypi/pygments@2.20.0",
"resource": "pygments"
},
{
"strategy": "registry",
"ecosystem": "PyPI",
"name": "pygments",
"subject_version": "2.20.0",
"key": "pkg:pypi/pygments@2.20.0",
"resource": "pygments"
}
]
},
"summary": "Command Injection in Pygments",
"details": "The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-8557"
},
{
"type": "WEB",
"url": "https://github.com/pygments/pygments/commit/db6dd826f8624179e563aaded391efe824462f51"
},
{
"type": "WEB",
"url": "https://bitbucket.org/birkenfeld/pygments-main/pull-requests/501/fix-shell-injection-in/diff"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-fff8-4w9p-7v76"
},
{
"type": "PACKAGE",
"url": "https://github.com/pygments/pygments"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2016-32.yaml"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/201612-05"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_path-Shell-Injection.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2015/Oct/4"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2016/dsa-3445"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2015/12/14/17"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2015/12/14/6"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-2862-1"
}
]
}
Loading