pythonware records
3 published records for vendor pythonware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2014-3007No exploit | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharactpython · pillow · CWE-78 | Critical10.0 | — | 11.6% | Apr 27, 2014 |
17Monitor | CVE-2014-1932No exploit | The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, apython · pillow · CWE-59 | Medium4.4 | — | 0.5% | Apr 17, 2014 |
8Monitor | CVE-2014-1933No exploit | The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses thpython · pillow · CWE-264 | Low2.1 | — | 0.5% | Apr 17, 2014 |
- CVE-2014-300743Plan
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact
CriticalCVSS 10.0No exploitEPSS 12%python · pillowApr 27, 2014
- CVE-2014-193217Monitor
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, a
MediumCVSS 4.4No exploitEPSS 0%python · pillowApr 17, 2014
- CVE-2014-19338Monitor
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses th
LowCVSS 2.1No exploitEPSS 0%python · pillowApr 17, 2014