Python Software Foundation records
9 published records for vendor python software foundation.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 77.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-12254No exploit | Unbounded memory buffering in SelectorSocketTransport.writelines()python software foundation · cpython · CWE-400 | High8.7 | — | 1.9% | Dec 6, 2024 |
34Monitor | CVE-2024-8088No exploit | Infinite loop when iterating over zip archive entry names from zipfile.Pathpython software foundation · cpython · CWE-835 | High8.7 | — | 1.3% | Aug 22, 2024 |
31Monitor | CVE-2007-1657Proof of concept | Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to exepython software foundation · python | High7.5 | — | 4.7% | Mar 23, 2007 |
31Monitor | CVE-2023-6597No exploit | An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and pripython software foundation · cpython | High7.8 | — | 0.3% | Mar 19, 2024 |
29Monitor | CVE-2024-0397No exploit | Memory race condition in ssl.SSLContext certificate store methodspython software foundation · cpython · CWE-362 | High7.4 | — | 0.8% | Jun 17, 2024 |
28Monitor | CVE-2008-4108No exploit | Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files vipython software foundation · python · CWE-59 | High7.2 | — | 0.4% | Sep 18, 2008 |
25Monitor | CVE-2024-11168No exploit | Improper validation of IPv6 and IPvFuture addressespython software foundation · cpython · CWE-918 | Medium6.3 | — | 0.7% | Nov 12, 2024 |
21Monitor | CVE-2024-21503No exploit | Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_eCWE-1333 | Medium5.3 | — | 1.0% | Mar 19, 2024 |
17Monitor | CVE-2008-0299No exploit | common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session python software foundation · paramiko | Medium4.3 | — | 1.6% | Jan 16, 2008 |
- CVE-2024-1225435Monitor
Unbounded memory buffering in SelectorSocketTransport.writelines()
HighCVSS 8.7No exploitEPSS 2%python software foundation · cpythonDec 6, 2024
- CVE-2024-808834Monitor
Infinite loop when iterating over zip archive entry names from zipfile.Path
HighCVSS 8.7No exploitEPSS 1%python software foundation · cpythonAug 22, 2024
- CVE-2007-165731Monitor
Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to exe
HighCVSS 7.5Proof of conceptEPSS 5%python software foundation · pythonMar 23, 2007
- CVE-2023-659731Monitor
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and pri
HighCVSS 7.8No exploitEPSS 0%python software foundation · cpythonMar 19, 2024
- CVE-2024-039729Monitor
Memory race condition in ssl.SSLContext certificate store methods
HighCVSS 7.4No exploitEPSS 1%python software foundation · cpythonJun 17, 2024
- CVE-2008-410828Monitor
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files vi
HighCVSS 7.2No exploitEPSS 0%python software foundation · pythonSep 18, 2008
- CVE-2024-1116825Monitor
Improper validation of IPv6 and IPvFuture addresses
MediumCVSS 6.3No exploitEPSS 1%python software foundation · cpythonNov 12, 2024
- CVE-2024-2150321Monitor
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_e
MediumCVSS 5.3No exploitEPSS 1%Mar 19, 2024
- CVE-2008-029917Monitor
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session
MediumCVSS 4.3No exploitEPSS 2%python software foundation · paramikoJan 16, 2008