Записи pyyaml
7 опубликованных записей вендора pyyaml.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-502 Deserialization of Untrusted Data2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-14343Proof of concept | A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it propyyaml · pyyaml · CWE-20 | Критическая9,8 | — | 6,0 % | 9 февр. 2021 г. |
41В плане | CVE-2017-18342Эксплойта нет | In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data.pyyaml · pyyaml · CWE-502 | Критическая9,8 | — | 5,7 % | 27 июн. 2018 г. |
41В плане | CVE-2020-1747Эксплойта нет | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it ppyyaml · pyyaml · CWE-20 | Критическая9,8 | — | 5,4 % | 24 мар. 2020 г. |
41В плане | CVE-2019-20477Эксплойта нет | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popyyaml · pyyaml · CWE-502 | Критическая9,8 | — | 5,1 % | 19 февр. 2020 г. |
30Наблюдать | CVE-2014-2525Эксплойта нет | Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to executpyyaml · libyaml · CWE-119 | Средняя6,8 | — | 8,8 % | 28 мар. 2014 г. |
29Наблюдать | CVE-2013-6393Эксплойта нет | The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to causpyyaml · libyaml · CWE-119 | Средняя6,8 | — | 7,4 % | 6 февр. 2014 г. |
24Наблюдать | CVE-2014-9130Эксплойта нет | scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to causepyyaml · libyaml · CWE-20 | Средняя5,0 | — | 13,2 % | 8 дек. 2014 г. |
- CVE-2020-1434341В плане
A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it pro
КритическаяCVSS 9,8Proof of conceptEPSS 6 %pyyaml · pyyaml9 февр. 2021 г.
- CVE-2017-1834241В плане
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %pyyaml · pyyaml27 июн. 2018 г.
- CVE-2020-174741В плане
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it p
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pyyaml · pyyaml24 мар. 2020 г.
- CVE-2019-2047741В плане
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Po
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pyyaml · pyyaml19 февр. 2020 г.
- CVE-2014-252530Наблюдать
Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execut
СредняяCVSS 6,8Эксплойта нетEPSS 9 %pyyaml · libyaml28 мар. 2014 г.
- CVE-2013-639329Наблюдать
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to caus
СредняяCVSS 6,8Эксплойта нетEPSS 7 %pyyaml · libyaml6 февр. 2014 г.
- CVE-2014-913024Наблюдать
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause
СредняяCVSS 5,0Эксплойта нетEPSS 13 %pyyaml · libyaml8 дек. 2014 г.