pygments records
4 published records for vendor pygments.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2015-8557No exploit | The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrarpygments · pygments · CWE-78 | Critical9.0 | — | 6.7% | Jan 8, 2016 |
31Monitor | CVE-2021-27291No exploit | In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions.pygments · pygments · CWE-1333 | High7.5 | — | 3.9% | Mar 17, 2021 |
31Monitor | CVE-2021-20270No exploit | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standapygments · pygments · CWE-835 | High7.5 | — | 2.8% | Mar 23, 2021 |
22Monitor | CVE-2022-40896No exploit | A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.pygments · pygments · CWE-434 | Medium5.5 | — | 0.5% | Jul 19, 2023 |
- CVE-2015-855738Monitor
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrar
CriticalCVSS 9.0No exploitEPSS 7%pygments · pygmentsJan 8, 2016
- CVE-2021-2729131Monitor
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions.
HighCVSS 7.5No exploitEPSS 4%pygments · pygmentsMar 17, 2021
- CVE-2021-2027031Monitor
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standa
HighCVSS 7.5No exploitEPSS 3%pygments · pygmentsMar 23, 2021
- CVE-2022-4089622Monitor
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
MediumCVSS 5.5No exploitEPSS 1%pygments · pygmentsJul 19, 2023