Skip to content
Noroxi

python records

280 published records for vendor python.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.4%
Pre-auth RCE
22
With a fix record
94.6%
Median publish → KEV
No record has entered KEV

All records

280 records
  • OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi

    HighCVSS 7.4WeaponizedEPSS 95%

    openssl · opensslJun 5, 2014

  • The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    HighCVSS 7.5Proof of conceptEPSS 95%

    redhat · jboss enterprise application platformAug 31, 2016

  • Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    python · pythonAug 27, 2007

  • Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all

    CriticalCVSS 9.8Proof of conceptEPSS 25%

    python · pythonSep 2, 2016

  • zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    HighCVSS 7.5Proof of conceptEPSS 52%

    zlib · zlibMar 25, 2022

  • The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al

    CriticalCVSS 9.8Proof of conceptEPSS 25%

    python · pythonFeb 20, 2020

  • Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth

    CriticalCVSS 9.8No exploitEPSS 23%

    python · pythonJan 19, 2021

  • Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C

    CriticalCVSS 9.8Proof of conceptEPSS 20%

    python · pythonSep 18, 2018

  • Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum

    CriticalCVSS 9.8No exploitEPSS 13%

    mozilla · firefoxMay 26, 2016

  • Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact

    CriticalCVSS 10.0No exploitEPSS 12%

    python · pillowApr 27, 2014

  • Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF

    CriticalCVSS 9.8No exploitEPSS 9%

    python · pythonMar 8, 2019

  • In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

    CriticalCVSS 9.8No exploitEPSS 8%

    python · pythonOct 21, 2020

  • BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

    CriticalCVSS 9.8No exploitEPSS 8%

    bzip · bzip2Jun 19, 2019

  • CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in

    CriticalCVSS 9.8No exploitEPSS 8%

    python · pythonNov 17, 2017

  • Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u

    CriticalCVSS 9.8No exploitEPSS 8%

    python · pillowApr 13, 2016

  • In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.

    CriticalCVSS 9.8No exploitEPSS 7%

    python · pythonMay 6, 2021

  • The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to

    CriticalCVSS 9.8No exploitEPSS 6%

    extended keccak code package project · extended keccak code packageOct 21, 2022

  • An integer overflow during the parsing of XML using the Expat library.

    CriticalCVSS 9.8No exploitEPSS 5%

    mozilla · firefoxJun 11, 2018

  • A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7

    CriticalCVSS 9.8No exploitEPSS 5%

    python · pythonJun 7, 2019

  • An XML External Entity (XXE) issue was discovered in Python through 3.9.1.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    python · pythonAug 22, 2023

  • Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i

    CriticalCVSS 10.0No exploitEPSS 3%

    python · pythonNov 10, 2008

  • urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani

    CriticalCVSS 9.1No exploitEPSS 12%

    python · pythonMar 23, 2019

  • An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.

    CriticalCVSS 9.8No exploitEPSS 5%

    python · tablibJun 14, 2017

  • urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff

    CriticalCVSS 9.8No exploitEPSS 4%

    python · urllib3Dec 11, 2018

  • An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.

    CriticalCVSS 9.8No exploitEPSS 4%

    python · jw.utilMay 22, 2020