numpy records
8 published records for vendor numpy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
- CWE-502 Deserialization of Untrusted Data1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-697 Incorrect Comparison1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2019-6446Proof of concept | An issue was discovered in NumPy before 1.16.3.numpy · numpy · CWE-502 | Critical9.8 | — | 17.5% | Jan 16, 2019 |
31Monitor | CVE-2017-12852Proof of concept | The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation.numpy · numpy · CWE-835 | High7.5 | — | 2.7% | Aug 15, 2017 |
22Monitor | CVE-2014-1859No exploit | (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allnumpy · numpy · CWE-59 | Medium5.5 | — | 0.5% | Jan 8, 2018 |
22Monitor | CVE-2014-1858No exploit | __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.numpy · numpy · CWE-20 | Medium5.5 | — | 0.4% | Jan 8, 2018 |
22Monitor | CVE-2021-41496No exploit | Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service anumpy · numpy · CWE-120 | Medium5.5 | — | 0.4% | Dec 17, 2021 |
21Monitor | CVE-2021-34141No exploit | An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying bynumpy · numpy · CWE-697 | Medium5.3 | — | 1.6% | Dec 17, 2021 |
21Monitor | CVE-2021-41495No exploit | Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-valnumpy · numpy · CWE-476 | Medium5.3 | — | 1.2% | Dec 17, 2021 |
21Monitor | CVE-2021-33430No exploit | A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dinumpy · numpy · CWE-120 | Medium5.3 | — | 1.1% | Dec 17, 2021 |
- CVE-2019-644644Plan
An issue was discovered in NumPy before 1.16.3.
CriticalCVSS 9.8Proof of conceptEPSS 18%numpy · numpyJan 16, 2019
- CVE-2017-1285231Monitor
The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation.
HighCVSS 7.5Proof of conceptEPSS 3%numpy · numpyAug 15, 2017
- CVE-2014-185922Monitor
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 all
MediumCVSS 5.5No exploitEPSS 0%numpy · numpyJan 8, 2018
- CVE-2014-185822Monitor
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
MediumCVSS 5.5No exploitEPSS 0%numpy · numpyJan 8, 2018
- CVE-2021-4149622Monitor
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service a
MediumCVSS 5.5No exploitEPSS 0%numpy · numpyDec 17, 2021
- CVE-2021-3414121Monitor
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by
MediumCVSS 5.3No exploitEPSS 2%numpy · numpyDec 17, 2021
- CVE-2021-4149521Monitor
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-val
MediumCVSS 5.3No exploitEPSS 1%numpy · numpyDec 17, 2021
- CVE-2021-3343021Monitor
A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large di
MediumCVSS 5.3No exploitEPSS 1%numpy · numpyDec 17, 2021