CyberSec.Space Logo
Back to CVE Browser

CVE-2014-0474

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0320%
EPSS Percentile9.44th
PublishedApr 23, 2014
Last ModifiedMay 6, 2026

Vulnerability Description

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

Affected Platforms (CPE)

πŸ’»
Canonical

Ubuntu Linux

= 10.04
πŸ’»
Canonical

Ubuntu Linux

= 12.04
πŸ’»
Canonical

Ubuntu Linux

= 12.10
πŸ’»
Canonical

Ubuntu Linux

= 13.10
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ“¦
Djangoproject

Django

= 1.6
πŸ“¦
Djangoproject

Django

= 1.6.1
πŸ“¦
Djangoproject

Django

= 1.6.2
πŸ“¦
Djangoproject

Django

<= 1.4.10
πŸ“¦
Djangoproject

Django

= 1.4
πŸ“¦
Djangoproject

Django

= 1.4.1
πŸ“¦
Djangoproject

Django

= 1.4.2
πŸ“¦
Djangoproject

Django

= 1.4.3
πŸ“¦
Djangoproject

Django

= 1.4.4
πŸ“¦
Djangoproject

Django

= 1.4.5
πŸ“¦
Djangoproject

Django

= 1.4.6
πŸ“¦
Djangoproject

Django

= 1.4.7
πŸ“¦
Djangoproject

Django

= 1.4.8
πŸ“¦
Djangoproject

Django

= 1.4.9
πŸ“¦
Djangoproject

Django

= 1.7
πŸ“¦
Djangoproject

Django

= 1.7
πŸ“¦
Djangoproject

Django

= 1.7
πŸ“¦
Djangoproject

Django

= 1.5
πŸ“¦
Djangoproject

Django

= 1.5.1
πŸ“¦
Djangoproject

Django

= 1.5.2
πŸ“¦
Djangoproject

Django

= 1.5.3
πŸ“¦
Djangoproject

Django

= 1.5.4
πŸ“¦
Djangoproject

Django

= 1.5.5

References & Advisories

Related Vulnerabilities