Seth Larson
19 kredili kayıt · son 12 ayda 9 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
21İzleyin | CVE-2026-6357İstismar yok | pip self-update functionality can import newly installed modules after wheel installationpip maintainers · pip · CWE-829 | Orta5,3 | — | %0,2 | 27 Nis 2026 |
28İzleyin | CVE-2026-4786İstismar yok | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()python software foundation · cpython · CWE-77 | Yüksek7,0 | — | %0,5 | 13 Nis 2026 |
36İzleyin | CVE-2026-6100İstismar yok | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressurepython software foundation · cpython · CWE-416 | Kritik9,1 | — | %0,8 | 13 Nis 2026 |
22İzleyin | CVE-2026-1502İstismar yok | HTTP client proxy tunnel headers not validated for CR/LFpython software foundation · cpython · CWE-93 | Orta5,7 | — | %0,6 | 10 Nis 2026 |
28İzleyin | CVE-2026-4519İstismar yok | webbrowser.open() allows leading dashes in URLspython · python · CWE-20 | Yüksek7,0 | — | %0,4 | 20 Mar 2026 |
24İzleyin | CVE-2026-3644İstismar yok | Incomplete control character validation in http.cookiespython · python · CWE-20 | Orta6,0 | — | %0,7 | 16 Mar 2026 |
22İzleyin | CVE-2025-11468İstismar yok | Folding email comments of unfoldable characters doesn't preserve parenthesispython software foundation · cpython · CWE-93 | Orta5,7 | — | %0,6 | 20 Oca 2026 |
25İzleyin | CVE-2025-12084İstismar yok | Quadratic complexity in node ID cache clearingpython · python · CWE-407 | Orta6,3 | — | %0,8 | 3 Ara 2025 |
17İzleyin | CVE-2025-8291İstismar yok | ZIP64 End of Central Directory (EOCD) Locator record offset not checkedpython software foundation · cpython · CWE-1285 | Orta4,3 | — | %0,4 | 7 Eki 2025 |
30İzleyin | CVE-2025-8194İstismar yok | Tarfile infinite loop during parsing with negative member offsetpython software foundation · cpython · CWE-835 | Yüksek7,5 | — | %0,7 | 28 Tem 2025 |
37İzleyin | CVE-2025-4517Kavram kanıtı | Arbitrary writes via tarfile realpath overflowpython software foundation · cpython · CWE-22 | Kritik9,4 | — | %1,4 | 3 Haz 2025 |
30İzleyin | CVE-2025-4435İstismar yok | Tarfile extracts filtered members when errorlevel=0python software foundation · cpython · CWE-682 | Yüksek7,5 | — | %0,6 | 3 Haz 2025 |
30İzleyin | CVE-2025-4330İstismar yok | Extraction filter bypass for linking outside extraction directorypython software foundation · cpython · CWE-22 | Yüksek7,5 | — | %0,9 | 3 Haz 2025 |
30İzleyin | CVE-2025-4138Kavram kanıtı | Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directorypython software foundation · cpython · CWE-22 | Yüksek7,5 | — | %1,4 | 3 Haz 2025 |
21İzleyin | CVE-2024-12718İstismar yok | Bypass extraction filter to modify file metadata outside extraction directorypython software foundation · cpython · CWE-22 | Orta5,3 | — | %0,8 | 3 Haz 2025 |
35İzleyin | CVE-2024-12254İstismar yok | Unbounded memory buffering in SelectorSocketTransport.writelines()python software foundation · cpython · CWE-400 | Yüksek8,7 | — | %1,9 | 6 Ara 2024 |
31İzleyin | CVE-2024-6232Kavram kanıtı | Regular-expression DoS when parsing TarFile headerspython · python · CWE-1333 | Yüksek7,5 | — | %2,2 | 3 Eyl 2024 |
34İzleyin | CVE-2024-8088İstismar yok | Infinite loop when iterating over zip archive entry names from zipfile.Pathpython software foundation · cpython · CWE-835 | Yüksek8,7 | — | %1,3 | 22 Ağu 2024 |
22İzleyin | CVE-2024-6923İstismar yok | Email header injection due to unquoted newlinespython software foundation · cpython · CWE-94 | Orta5,5 | — | %1,1 | 1 Ağu 2024 |
- CVE-2026-635721İzleyin
pip self-update functionality can import newly installed modules after wheel installation
OrtaCVSS 5,3İstismar yokEPSS %0pip maintainers · pip27 Nis 2026
- CVE-2026-478628İzleyin
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
YüksekCVSS 7,0İstismar yokEPSS %0python software foundation · cpython13 Nis 2026
- CVE-2026-610036İzleyin
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
KritikCVSS 9,1İstismar yokEPSS %1python software foundation · cpython13 Nis 2026
- CVE-2026-150222İzleyin
HTTP client proxy tunnel headers not validated for CR/LF
OrtaCVSS 5,7İstismar yokEPSS %1python software foundation · cpython10 Nis 2026
- CVE-2026-451928İzleyin
webbrowser.open() allows leading dashes in URLs
YüksekCVSS 7,0İstismar yokEPSS %0python · python20 Mar 2026
- CVE-2026-364424İzleyin
Incomplete control character validation in http.cookies
OrtaCVSS 6,0İstismar yokEPSS %1python · python16 Mar 2026
- CVE-2025-1146822İzleyin
Folding email comments of unfoldable characters doesn't preserve parenthesis
OrtaCVSS 5,7İstismar yokEPSS %1python software foundation · cpython20 Oca 2026
- CVE-2025-1208425İzleyin
Quadratic complexity in node ID cache clearing
OrtaCVSS 6,3İstismar yokEPSS %1python · python3 Ara 2025
- CVE-2025-829117İzleyin
ZIP64 End of Central Directory (EOCD) Locator record offset not checked
OrtaCVSS 4,3İstismar yokEPSS %0python software foundation · cpython7 Eki 2025
- CVE-2025-819430İzleyin
Tarfile infinite loop during parsing with negative member offset
YüksekCVSS 7,5İstismar yokEPSS %1python software foundation · cpython28 Tem 2025
- CVE-2025-451737İzleyin
Arbitrary writes via tarfile realpath overflow
KritikCVSS 9,4Kavram kanıtıEPSS %1python software foundation · cpython3 Haz 2025
- CVE-2025-443530İzleyin
Tarfile extracts filtered members when errorlevel=0
YüksekCVSS 7,5İstismar yokEPSS %1python software foundation · cpython3 Haz 2025
- CVE-2025-433030İzleyin
Extraction filter bypass for linking outside extraction directory
YüksekCVSS 7,5İstismar yokEPSS %1python software foundation · cpython3 Haz 2025
- CVE-2025-413830İzleyin
Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory
YüksekCVSS 7,5Kavram kanıtıEPSS %1python software foundation · cpython3 Haz 2025
- CVE-2024-1271821İzleyin
Bypass extraction filter to modify file metadata outside extraction directory
OrtaCVSS 5,3İstismar yokEPSS %1python software foundation · cpython3 Haz 2025
- CVE-2024-1225435İzleyin
Unbounded memory buffering in SelectorSocketTransport.writelines()
YüksekCVSS 8,7İstismar yokEPSS %2python software foundation · cpython6 Ara 2024
- CVE-2024-623231İzleyin
Regular-expression DoS when parsing TarFile headers
YüksekCVSS 7,5Kavram kanıtıEPSS %2python · python3 Eyl 2024
- CVE-2024-808834İzleyin
Infinite loop when iterating over zip archive entry names from zipfile.Path
YüksekCVSS 8,7İstismar yokEPSS %1python software foundation · cpython22 Ağu 2024
- CVE-2024-692322İzleyin
Email header injection due to unquoted newlines
OrtaCVSS 5,5İstismar yokEPSS %1python software foundation · cpython1 Ağu 2024