python records
280 published records for vendor python.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.4%
- Pre-auth RCE
- 22
- With a fix record
- 94.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound21
- CWE-20 Improper Input Validation19
- CWE-125 Out-of-bounds Read18
- CWE-400 Uncontrolled Resource Consumption17
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')10
- CWE-787 Out-of-bounds Write10
The weakness classes this vendor ships most often: where to look.
CWEAll records
280 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2014-0224Weaponized | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | High7.4 | — | 95.3% | Jun 5, 2014 |
58Plan | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | High7.5 | — | 94.7% | Aug 31, 2016 |
47Plan | CVE-2007-4559Proof of concept | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remotpython · python · CWE-22 | Critical9.8 | — | 27.1% | Aug 27, 2007 |
47Plan | CVE-2016-5636Proof of concept | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allpython · python · CWE-190 | Critical9.8 | — | 25.5% | Sep 2, 2016 |
46Plan | CVE-2018-25032Proof of concept | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | High7.5 | — | 51.7% | Mar 25, 2022 |
46Plan | CVE-2014-4650Proof of concept | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which alpython · python · CWE-22 | Critical9.8 | — | 24.7% | Feb 20, 2020 |
46Plan | CVE-2021-3177No exploit | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pythpython · python · CWE-120 | Critical9.8 | — | 23.3% | Jan 19, 2021 |
45Plan | CVE-2018-1000802Proof of concept | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Cpython · python · CWE-77 | Critical9.8 | — | 20.1% | Sep 18, 2018 |
43Plan | CVE-2016-0718No exploit | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docummozilla · firefox · CWE-119 | Critical9.8 | — | 13.3% | May 26, 2016 |
43Plan | CVE-2014-3007No exploit | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharactpython · pillow · CWE-78 | Critical10.0 | — | 11.6% | Apr 27, 2014 |
42Plan | CVE-2019-9636No exploit | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFpython · python | Critical9.8 | — | 8.8% | Mar 8, 2019 |
42Plan | CVE-2020-27619No exploit | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.python · python | Critical9.8 | — | 8.3% | Oct 21, 2020 |
41Plan | CVE-2019-12900No exploit | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Critical9.8 | — | 8.0% | Jun 19, 2019 |
41Plan | CVE-2017-1000158No exploit | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting inpython · python · CWE-190 | Critical9.8 | — | 7.9% | Nov 17, 2017 |
41Plan | CVE-2016-4009No exploit | Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have upython · pillow · CWE-119 | Critical9.8 | — | 7.9% | Apr 13, 2016 |
41Plan | CVE-2021-29921No exploit | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.python · python | Critical9.8 | — | 6.9% | May 6, 2021 |
41Plan | CVE-2022-37454No exploit | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers toextended keccak code package project · extended keccak code package · CWE-190 | Critical9.8 | — | 5.8% | Oct 21, 2022 |
41Plan | CVE-2016-9063No exploit | An integer overflow during the parsing of XML using the Expat library.mozilla · firefox · CWE-190 | Critical9.8 | — | 5.5% | Jun 11, 2018 |
41Plan | CVE-2019-10160No exploit | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7python · python · CWE-172 | Critical9.8 | — | 5.2% | Jun 7, 2019 |
41Plan | CVE-2022-48565Proof of concept | An XML External Entity (XXE) issue was discovered in Python through 3.9.1.python · python · CWE-611 | Critical9.8 | — | 5.1% | Aug 22, 2023 |
41Plan | CVE-2008-5031No exploit | Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large ipython · python · CWE-189 | Critical10.0 | — | 3.0% | Nov 10, 2008 |
40Plan | CVE-2019-9948No exploit | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanipython · python · CWE-22 | Critical9.1 | — | 11.8% | Mar 23, 2019 |
40Plan | CVE-2017-2810No exploit | An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.python · tablib | Critical9.8 | — | 4.9% | Jun 14, 2017 |
40Plan | CVE-2018-20060No exploit | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diffpython · urllib3 | Critical9.8 | — | 4.5% | Dec 11, 2018 |
40Plan | CVE-2020-13388No exploit | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.python · jw.util · CWE-78 | Critical9.8 | — | 4.4% | May 22, 2020 |
- CVE-2014-022458Plan
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
HighCVSS 7.4WeaponizedEPSS 95%openssl · opensslJun 5, 2014
- CVE-2016-218358Plan
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
HighCVSS 7.5Proof of conceptEPSS 95%redhat · jboss enterprise application platformAug 31, 2016
- CVE-2007-455947Plan
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot
CriticalCVSS 9.8Proof of conceptEPSS 27%python · pythonAug 27, 2007
- CVE-2016-563647Plan
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all
CriticalCVSS 9.8Proof of conceptEPSS 25%python · pythonSep 2, 2016
- CVE-2018-2503246Plan
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
HighCVSS 7.5Proof of conceptEPSS 52%zlib · zlibMar 25, 2022
- CVE-2014-465046Plan
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al
CriticalCVSS 9.8Proof of conceptEPSS 25%python · pythonFeb 20, 2020
- CVE-2021-317746Plan
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth
CriticalCVSS 9.8No exploitEPSS 23%python · pythonJan 19, 2021
- CVE-2018-100080245Plan
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C
CriticalCVSS 9.8Proof of conceptEPSS 20%python · pythonSep 18, 2018
- CVE-2016-071843Plan
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum
CriticalCVSS 9.8No exploitEPSS 13%mozilla · firefoxMay 26, 2016
- CVE-2014-300743Plan
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact
CriticalCVSS 10.0No exploitEPSS 12%python · pillowApr 27, 2014
- CVE-2019-963642Plan
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF
CriticalCVSS 9.8No exploitEPSS 9%python · pythonMar 8, 2019
- CVE-2020-2761942Plan
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
CriticalCVSS 9.8No exploitEPSS 8%python · pythonOct 21, 2020
- CVE-2019-1290041Plan
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
CriticalCVSS 9.8No exploitEPSS 8%bzip · bzip2Jun 19, 2019
- CVE-2017-100015841Plan
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in
CriticalCVSS 9.8No exploitEPSS 8%python · pythonNov 17, 2017
- CVE-2016-400941Plan
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u
CriticalCVSS 9.8No exploitEPSS 8%python · pillowApr 13, 2016
- CVE-2021-2992141Plan
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.
CriticalCVSS 9.8No exploitEPSS 7%python · pythonMay 6, 2021
- CVE-2022-3745441Plan
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to
CriticalCVSS 9.8No exploitEPSS 6%extended keccak code package project · extended keccak code packageOct 21, 2022
- CVE-2016-906341Plan
An integer overflow during the parsing of XML using the Expat library.
CriticalCVSS 9.8No exploitEPSS 5%mozilla · firefoxJun 11, 2018
- CVE-2019-1016041Plan
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7
CriticalCVSS 9.8No exploitEPSS 5%python · pythonJun 7, 2019
- CVE-2022-4856541Plan
An XML External Entity (XXE) issue was discovered in Python through 3.9.1.
CriticalCVSS 9.8Proof of conceptEPSS 5%python · pythonAug 22, 2023
- CVE-2008-503141Plan
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i
CriticalCVSS 10.0No exploitEPSS 3%python · pythonNov 10, 2008
- CVE-2019-994840Plan
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani
CriticalCVSS 9.1No exploitEPSS 12%python · pythonMar 23, 2019
- CVE-2017-281040Plan
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.
CriticalCVSS 9.8No exploitEPSS 5%python · tablibJun 14, 2017
- CVE-2018-2006040Plan
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff
CriticalCVSS 9.8No exploitEPSS 4%python · urllib3Dec 11, 2018
- CVE-2020-1338840Plan
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.
CriticalCVSS 9.8No exploitEPSS 4%python · jw.utilMay 22, 2020