Перейти к содержимому
Noroxi

Записи pypa

11 опубликованных записей вендора pypa.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
90,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

11 записей
  • CVE-2022-21668
    35Наблюдать

    Pipenv's requirements.txt parsing allows malicious index url in comments

    ВысокаяCVSS 8,6Proof of conceptEPSS 4 %

    pypa · pipenv10 янв. 2022 г.

  • CVE-2018-20225
    32Наблюдать

    An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended

    ВысокаяCVSS 7,8Proof of conceptEPSS 2 %

    pypa · pip8 мая 2020 г.

  • CVE-2019-20916
    31Наблюдать

    The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition h

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    pypa · pip4 сент. 2020 г.

  • CVE-2013-1629
    29Наблюдать

    pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which all

    СредняяCVSS 6,8Эксплойта нетEPSS 6 %

    pypa · pip5 авг. 2013 г.

  • CVE-2013-5123
    25Наблюдать

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers

    СредняяCVSS 5,9Proof of conceptEPSS 8 %

    pypa · pip5 нояб. 2019 г.

  • CVE-2021-3572
    23Наблюдать

    A flaw was found in python-pip in the way it handled Unicode separators in git references.

    СредняяCVSS 5,7Proof of conceptEPSS 2 %

    pypa · pip10 нояб. 2021 г.

  • CVE-2026-13346
    22Наблюдать

    pip absolute path traversal during download from malicious package indexes

    СредняяCVSS 5,6Эксплойта нетEPSS 0 %

    pypa · pip29 июл. 2026 г.

  • CVE-2026-8643
    16Наблюдать

    pip can extract console_scripts and gui_scripts outside installation directory

    СредняяCVSS 4,1Эксплойта нетEPSS 0 %

    pypa · pip1 июн. 2026 г.

  • CVE-2023-5752
    13Наблюдать

    Mercurial configuration injectable in repo revision when installing via pip

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    pypa · pip25 окт. 2023 г.

  • CVE-2014-8991
    8Наблюдать

    pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fi

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    pypa · pip24 нояб. 2014 г.

  • CVE-2013-1888
    8Наблюдать

    pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    pypa · pip17 авг. 2013 г.