İçeriğe atla
Noroxi

pypa kayıtları

pypa üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%90,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2022-21668
    35İzleyin

    Pipenv's requirements.txt parsing allows malicious index url in comments

    YüksekCVSS 8,6Kavram kanıtıEPSS %4

    pypa · pipenv10 Oca 2022

  • CVE-2018-20225
    32İzleyin

    An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    pypa · pip8 May 2020

  • CVE-2019-20916
    31İzleyin

    The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition h

    YüksekCVSS 7,5İstismar yokEPSS %3

    pypa · pip4 Eyl 2020

  • CVE-2013-1629
    29İzleyin

    pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which all

    OrtaCVSS 6,8İstismar yokEPSS %6

    pypa · pip5 Ağu 2013

  • CVE-2013-5123
    25İzleyin

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers

    OrtaCVSS 5,9Kavram kanıtıEPSS %8

    pypa · pip5 Kas 2019

  • CVE-2021-3572
    23İzleyin

    A flaw was found in python-pip in the way it handled Unicode separators in git references.

    OrtaCVSS 5,7Kavram kanıtıEPSS %2

    pypa · pip10 Kas 2021

  • CVE-2026-13346
    22İzleyin

    pip absolute path traversal during download from malicious package indexes

    OrtaCVSS 5,6İstismar yokEPSS %0

    pypa · pip29 Tem 2026

  • CVE-2026-8643
    16İzleyin

    pip can extract console_scripts and gui_scripts outside installation directory

    OrtaCVSS 4,1İstismar yokEPSS %0

    pypa · pip1 Haz 2026

  • CVE-2023-5752
    13İzleyin

    Mercurial configuration injectable in repo revision when installing via pip

    DüşükCVSS 3,3İstismar yokEPSS %0

    pypa · pip25 Eki 2023

  • CVE-2014-8991
    8İzleyin

    pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fi

    DüşükCVSS 2,1İstismar yokEPSS %0

    pypa · pip24 Kas 2014

  • CVE-2013-1888
    8İzleyin

    pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

    DüşükCVSS 2,1İstismar yokEPSS %0

    pypa · pip17 Ağu 2013