python2-lockfile

Direct Vulnerabilities

Known vulnerabilities in the python2-lockfile package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Directory Traversal

<1:0.11.0-10.el7ar
  • M
Information Exposure

<1:0.11.0-10.el7ar
  • M
Missing Authorization

<1:0.11.0-10.el7ar
  • M
Information Exposure Through Log Files

<1:0.11.0-10.el7ar
  • H
Improper Input Validation

<1:0.11.0-10.el7ar
  • H
Cross-site Scripting (XSS)

<1:0.11.0-10.el7ar
  • M
Information Exposure

<1:0.11.0-10.el7ar
  • M
Incorrect Permission Assignment for Critical Resource

<1:0.11.0-10.el7ar
  • M
Cleartext Storage of Sensitive Information

<1:0.11.0-10.el7ar
  • M
Improper Authentication

<1:0.11.0-10.el7ar
  • H
Improper Authorization

<1:0.11.0-10.el7ar
  • H
Cleartext Transmission of Sensitive Information

<1:0.11.0-10.el7ar
  • H
Improper Certificate Validation

<1:0.11.0-10.el7ar
  • H
Insufficiently Protected Credentials

<1:0.11.0-10.el7ar
  • H
Improper Authentication

<1:0.11.0-10.el7ar
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7ar
  • M
Information Exposure

<1:0.11.0-10.el7ar
  • H
Information Exposure

<1:0.11.0-10.el7ar
  • H
Binding to an Unrestricted IP Address

<1:0.11.0-10.el7ar
  • M
SQL Injection

<1:0.11.0-10.el7ar
  • H
Improperly Implemented Security Check for Standard

<1:0.11.0-10.el7ar
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
XML External Entity (XXE) Injection

<1:0.11.0-10.el7at
  • M
XML External Entity (XXE) Injection

<1:0.11.0-10.el7at
  • H
Missing Authorization

<1:0.11.0-10.el7ar
  • H
Improper Validation of Certificate with Host Mismatch

<1:0.11.0-10.el7ar
  • M
Execution with Unnecessary Privileges

<1:0.11.0-10.el7ar
  • H
HTTP Request Smuggling

<1:0.11.0-10.el7ar
  • M
Resource Exhaustion

<1:0.11.0-10.el7ar
  • M
Allocation of Resources Without Limits or Throttling

<1:0.11.0-10.el7ar
  • M
Information Exposure

<1:0.11.0-10.el7ar
  • M
Cross-site Request Forgery (CSRF)

<1:0.11.0-10.el7ar
  • H
Cross-site Scripting (XSS)

<1:0.11.0-10.el7ar
  • M
Cross-site Request Forgery (CSRF)

<1:0.11.0-10.el7ar
  • H
Inefficient Regular Expression Complexity

<1:0.11.0-10.el7ar
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7ar
  • M
Improper Input Validation

<1:0.11.0-10.el7ar
  • M
Improper Input Validation

<1:0.11.0-10.el7ar
  • H
Arbitrary Code Injection

<1:0.11.0-10.el7ar
  • H
Directory Traversal

<1:0.11.0-10.el7ar
  • H
CRLF Injection

<1:0.11.0-10.el7ar
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:0.11.0-10.el7ar
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
Cross-site Scripting (XSS)

<1:0.11.0-10.el7at
  • M
HTTP Response Splitting

<1:0.11.0-10.el7ar
  • H
CVE-2018-3258

<1:0.11.0-10.el7ar
  • M
Covert Timing Channel

<1:0.11.0-10.el7ar
  • H
Covert Timing Channel

<1:0.11.0-10.el7ar
  • M
Arbitrary Argument Injection

<1:0.11.0-10.el7ar
  • M
Improper Neutralization of Special Elements

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • M
Improper Neutralization of Special Elements

<1:0.11.0-10.el7ar
  • M
Information Exposure

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar
  • M
Use After Free

<1:0.11.0-10.el7ar
  • H
Deserialization of Untrusted Data

<1:0.11.0-10.el7ar