Перейти к содержимому
Noroxi

Записи python

280 опубликованных записей вендора python.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 0,4 %
Pre-auth RCE
22
С записью об исправлении
94,6 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 16
  2. 17
  3. 18
  4. 19
  5. 20
  6. 21
  7. 22
  8. 23
  9. 24
  10. 25
  11. 26

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

280 записей
  • CVE-2014-0224
    58В плане

    OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi

    ВысокаяCVSS 7,4Готовый эксплойтEPSS 95 %

    openssl · openssl5 июн. 2014 г.

  • CVE-2016-2183
    58В плане

    The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    ВысокаяCVSS 7,5Proof of conceptEPSS 95 %

    redhat · jboss enterprise application platform31 авг. 2016 г.

  • CVE-2007-4559
    47В плане

    Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot

    КритическаяCVSS 9,8Proof of conceptEPSS 27 %

    python · python27 авг. 2007 г.

  • CVE-2016-5636
    47В плане

    Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all

    КритическаяCVSS 9,8Proof of conceptEPSS 25 %

    python · python2 сент. 2016 г.

  • CVE-2018-25032
    46В плане

    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    ВысокаяCVSS 7,5Proof of conceptEPSS 52 %

    zlib · zlib25 мар. 2022 г.

  • CVE-2014-4650
    46В плане

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al

    КритическаяCVSS 9,8Proof of conceptEPSS 25 %

    python · python20 февр. 2020 г.

  • CVE-2021-3177
    46В плане

    Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth

    КритическаяCVSS 9,8Эксплойта нетEPSS 23 %

    python · python19 янв. 2021 г.

  • CVE-2018-1000802
    45В плане

    Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C

    КритическаяCVSS 9,8Proof of conceptEPSS 20 %

    python · python18 сент. 2018 г.

  • CVE-2016-0718
    43В плане

    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum

    КритическаяCVSS 9,8Эксплойта нетEPSS 13 %

    mozilla · firefox26 мая 2016 г.

  • CVE-2014-3007
    43В плане

    Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact

    КритическаяCVSS 10,0Эксплойта нетEPSS 12 %

    python · pillow27 апр. 2014 г.

  • CVE-2019-9636
    42В плане

    Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    python · python8 мар. 2019 г.

  • CVE-2020-27619
    42В плане

    In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    python · python21 окт. 2020 г.

  • CVE-2019-12900
    41В плане

    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    bzip · bzip219 июн. 2019 г.

  • CVE-2017-1000158
    41В плане

    CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    python · python17 нояб. 2017 г.

  • CVE-2016-4009
    41В плане

    Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    python · pillow13 апр. 2016 г.

  • CVE-2021-29921
    41В плане

    In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    python · python6 мая 2021 г.

  • CVE-2022-37454
    41В плане

    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    extended keccak code package project · extended keccak code package21 окт. 2022 г.

  • CVE-2016-9063
    41В плане

    An integer overflow during the parsing of XML using the Expat library.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    mozilla · firefox11 июн. 2018 г.

  • CVE-2019-10160
    41В плане

    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    python · python7 июн. 2019 г.

  • CVE-2022-48565
    41В плане

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1.

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    python · python22 авг. 2023 г.

  • CVE-2008-5031
    41В плане

    Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    python · python10 нояб. 2008 г.

  • CVE-2019-9948
    40В плане

    urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani

    КритическаяCVSS 9,1Эксплойта нетEPSS 12 %

    python · python23 мар. 2019 г.

  • CVE-2017-2810
    40В плане

    An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    python · tablib14 июн. 2017 г.

  • CVE-2018-20060
    40В плане

    urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    python · urllib311 дек. 2018 г.

  • CVE-2020-13388
    40В плане

    An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    python · jw.util22 мая 2020 г.