Перейти к содержимому
Noroxi

Petr Viktorin (https://github.com/encukou)

13 записей с упоминанием · 13 за 12 месяцев · 0 в CISA KEV

Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.

Записи с упоминанием

Исследователи
  • CVE-2026-12345
    23Наблюдать

    Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

    СредняяCVSS 5,9Эксплойта нет

    python software foundation · cpythonСегодня

  • CVE-2026-82049
    33Наблюдать

    tarfile extraction filters allow file modification and content disclosure via hard link to symlink

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    python software foundation · cpython14 сент. 2026 г.

  • CVE-2026-87910
    22Наблюдать

    tarfile hardlink fallback ignores custom extraction filter rejection via None

    СредняяCVSS 5,7Эксплойта нетEPSS 1 %

    python software foundation · cpython11 сент. 2026 г.

  • CVE-2026-15310
    8Наблюдать

    zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    НизкаяCVSS 2,1Эксплойта нетEPSS 1 %

    python software foundation · cpython25 авг. 2026 г.

  • CVE-2026-19672
    25Наблюдать

    tarfile extraction filter bypass allows creation of directories outside the destination

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    python software foundation · cpython19 авг. 2026 г.

  • CVE-2026-17084
    24Наблюдать

    stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    СредняяCVSS 6,0Эксплойта нетEPSS 1 %

    python software foundation · cpython18 авг. 2026 г.

  • CVE-2026-6879
    8Наблюдать

    Quadratic Behavior in xml.etree.ElementPath Index Predicates

    НизкаяCVSS 2,0Эксплойта нетEPSS 1 %

    python software foundation · cpython28 июл. 2026 г.

  • CVE-2026-4360
    8Наблюдать

    Tarfile.extract() doesn't fully respect filter parameter

    НизкаяCVSS 2,0Эксплойта нетEPSS 0 %

    python · python30 июн. 2026 г.

  • CVE-2026-11972
    32Наблюдать

    tarfile opened in streaming mode mishandles EOF

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    python software foundation · cpython23 июн. 2026 г.

  • CVE-2026-0864
    16Наблюдать

    Configuration Injection via Carriage Return (\r) in write() method

    СредняяCVSS 4,1Эксплойта нетEPSS 0 %

    python · python23 июн. 2026 г.

  • CVE-2026-11940
    31Наблюдать

    tarfile extraction filter bypass allows escaping the destination directory

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    python software foundation · cpython23 июн. 2026 г.

  • CVE-2026-7774
    27Наблюдать

    tarfile.data_filter path traversal bypass allows writing outside the extraction directory

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    python software foundation · cpython4 июн. 2026 г.

  • CVE-2026-3276
    25Наблюдать

    Potential DoS via quadratic complexity in unicodedata.normalize()

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    python software foundation · cpython3 июн. 2026 г.