Записи python
280 опубликованных записей вендора python.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,4 %
- Pre-auth RCE
- 22
- С записью об исправлении
- 94,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound21
- CWE-20 Improper Input Validation19
- CWE-125 Out-of-bounds Read18
- CWE-400 Uncontrolled Resource Consumption17
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')10
- CWE-787 Out-of-bounds Write10
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
280 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2014-0224Готовый эксплойт | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Высокая7,4 | — | 95,3 % | 5 июн. 2014 г. |
58В плане | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Высокая7,5 | — | 94,7 % | 31 авг. 2016 г. |
47В плане | CVE-2007-4559Proof of concept | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remotpython · python · CWE-22 | Критическая9,8 | — | 27,1 % | 27 авг. 2007 г. |
47В плане | CVE-2016-5636Proof of concept | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allpython · python · CWE-190 | Критическая9,8 | — | 25,5 % | 2 сент. 2016 г. |
46В плане | CVE-2018-25032Proof of concept | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | Высокая7,5 | — | 51,7 % | 25 мар. 2022 г. |
46В плане | CVE-2014-4650Proof of concept | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which alpython · python · CWE-22 | Критическая9,8 | — | 24,7 % | 20 февр. 2020 г. |
46В плане | CVE-2021-3177Эксплойта нет | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pythpython · python · CWE-120 | Критическая9,8 | — | 23,3 % | 19 янв. 2021 г. |
45В плане | CVE-2018-1000802Proof of concept | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Cpython · python · CWE-77 | Критическая9,8 | — | 20,1 % | 18 сент. 2018 г. |
43В плане | CVE-2016-0718Эксплойта нет | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docummozilla · firefox · CWE-119 | Критическая9,8 | — | 13,3 % | 26 мая 2016 г. |
43В плане | CVE-2014-3007Эксплойта нет | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharactpython · pillow · CWE-78 | Критическая10,0 | — | 11,6 % | 27 апр. 2014 г. |
42В плане | CVE-2019-9636Эксплойта нет | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFpython · python | Критическая9,8 | — | 8,8 % | 8 мар. 2019 г. |
42В плане | CVE-2020-27619Эксплойта нет | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.python · python | Критическая9,8 | — | 8,3 % | 21 окт. 2020 г. |
41В плане | CVE-2019-12900Эксплойта нет | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Критическая9,8 | — | 8,0 % | 19 июн. 2019 г. |
41В плане | CVE-2017-1000158Эксплойта нет | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting inpython · python · CWE-190 | Критическая9,8 | — | 7,9 % | 17 нояб. 2017 г. |
41В плане | CVE-2016-4009Эксплойта нет | Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have upython · pillow · CWE-119 | Критическая9,8 | — | 7,9 % | 13 апр. 2016 г. |
41В плане | CVE-2021-29921Эксплойта нет | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.python · python | Критическая9,8 | — | 6,9 % | 6 мая 2021 г. |
41В плане | CVE-2022-37454Эксплойта нет | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers toextended keccak code package project · extended keccak code package · CWE-190 | Критическая9,8 | — | 5,8 % | 21 окт. 2022 г. |
41В плане | CVE-2016-9063Эксплойта нет | An integer overflow during the parsing of XML using the Expat library.mozilla · firefox · CWE-190 | Критическая9,8 | — | 5,5 % | 11 июн. 2018 г. |
41В плане | CVE-2019-10160Эксплойта нет | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7python · python · CWE-172 | Критическая9,8 | — | 5,2 % | 7 июн. 2019 г. |
41В плане | CVE-2022-48565Proof of concept | An XML External Entity (XXE) issue was discovered in Python through 3.9.1.python · python · CWE-611 | Критическая9,8 | — | 5,1 % | 22 авг. 2023 г. |
41В плане | CVE-2008-5031Эксплойта нет | Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large ipython · python · CWE-189 | Критическая10,0 | — | 3,0 % | 10 нояб. 2008 г. |
40В плане | CVE-2019-9948Эксплойта нет | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanipython · python · CWE-22 | Критическая9,1 | — | 11,8 % | 23 мар. 2019 г. |
40В плане | CVE-2017-2810Эксплойта нет | An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.python · tablib | Критическая9,8 | — | 4,9 % | 14 июн. 2017 г. |
40В плане | CVE-2018-20060Эксплойта нет | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diffpython · urllib3 | Критическая9,8 | — | 4,5 % | 11 дек. 2018 г. |
40В плане | CVE-2020-13388Эксплойта нет | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.python · jw.util · CWE-78 | Критическая9,8 | — | 4,4 % | 22 мая 2020 г. |
- CVE-2014-022458В плане
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
ВысокаяCVSS 7,4Готовый эксплойтEPSS 95 %openssl · openssl5 июн. 2014 г.
- CVE-2016-218358В плане
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
ВысокаяCVSS 7,5Proof of conceptEPSS 95 %redhat · jboss enterprise application platform31 авг. 2016 г.
- CVE-2007-455947В плане
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot
КритическаяCVSS 9,8Proof of conceptEPSS 27 %python · python27 авг. 2007 г.
- CVE-2016-563647В плане
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all
КритическаяCVSS 9,8Proof of conceptEPSS 25 %python · python2 сент. 2016 г.
- CVE-2018-2503246В плане
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %zlib · zlib25 мар. 2022 г.
- CVE-2014-465046В плане
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al
КритическаяCVSS 9,8Proof of conceptEPSS 25 %python · python20 февр. 2020 г.
- CVE-2021-317746В плане
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %python · python19 янв. 2021 г.
- CVE-2018-100080245В плане
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C
КритическаяCVSS 9,8Proof of conceptEPSS 20 %python · python18 сент. 2018 г.
- CVE-2016-071843В плане
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %mozilla · firefox26 мая 2016 г.
- CVE-2014-300743В плане
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %python · pillow27 апр. 2014 г.
- CVE-2019-963642В плане
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %python · python8 мар. 2019 г.
- CVE-2020-2761942В плане
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %python · python21 окт. 2020 г.
- CVE-2019-1290041В плане
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %bzip · bzip219 июн. 2019 г.
- CVE-2017-100015841В плане
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %python · python17 нояб. 2017 г.
- CVE-2016-400941В плане
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %python · pillow13 апр. 2016 г.
- CVE-2021-2992141В плане
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %python · python6 мая 2021 г.
- CVE-2022-3745441В плане
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %extended keccak code package project · extended keccak code package21 окт. 2022 г.
- CVE-2016-906341В плане
An integer overflow during the parsing of XML using the Expat library.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mozilla · firefox11 июн. 2018 г.
- CVE-2019-1016041В плане
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %python · python7 июн. 2019 г.
- CVE-2022-4856541В плане
An XML External Entity (XXE) issue was discovered in Python through 3.9.1.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %python · python22 авг. 2023 г.
- CVE-2008-503141В плане
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %python · python10 нояб. 2008 г.
- CVE-2019-994840В плане
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani
КритическаяCVSS 9,1Эксплойта нетEPSS 12 %python · python23 мар. 2019 г.
- CVE-2017-281040В плане
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %python · tablib14 июн. 2017 г.
- CVE-2018-2006040В плане
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %python · urllib311 дек. 2018 г.
- CVE-2020-1338840В плане
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %python · jw.util22 мая 2020 г.