Vulnerabilities > Ipython

DATE CVE VULNERABILITY TITLE RISK
2023-02-10 CVE-2023-24816 OS Command Injection vulnerability in Ipython
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language.
local
high complexity
ipython CWE-78
7.0
2022-01-19 CVE-2022-21699 Incorrect Execution-Assigned Permissions vulnerability in multiple products
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language.
local
low complexity
ipython debian fedoraproject CWE-279
8.8
2017-09-21 CVE-2015-4706 Cross-site Scripting vulnerability in Ipython 3.0.0/3.1.0
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.
network
ipython CWE-79
4.3
2017-09-20 CVE-2015-4707 Cross-site Scripting vulnerability in Ipython
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.
network
ipython CWE-79
4.3
2017-09-20 CVE-2015-5607 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery in the REST API in IPython 2 and 3.
6.8
2015-09-29 CVE-2015-7337 Improper Input Validation vulnerability in multiple products
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
6.8
2015-09-21 CVE-2015-6938 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name.
4.3
2014-08-07 CVE-2014-3429 Code Injection vulnerability in multiple products
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
6.8