python kayıtları
python üreticisine ait 280 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,4
- Pre-auth RCE
- 22
- Düzeltme kaydı olan
- %94,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound21
- CWE-20 Improper Input Validation19
- CWE-125 Out-of-bounds Read18
- CWE-400 Uncontrolled Resource Consumption17
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')10
- CWE-787 Out-of-bounds Write10
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
280 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
58Planlayın | CVE-2016-2183Kavram kanıtı | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Yüksek7,5 | — | %94,7 | 31 Ağu 2016 |
47Planlayın | CVE-2007-4559Kavram kanıtı | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remotpython · python · CWE-22 | Kritik9,8 | — | %27,1 | 27 Ağu 2007 |
47Planlayın | CVE-2016-5636Kavram kanıtı | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allpython · python · CWE-190 | Kritik9,8 | — | %25,5 | 2 Eyl 2016 |
46Planlayın | CVE-2018-25032Kavram kanıtı | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | Yüksek7,5 | — | %51,7 | 25 Mar 2022 |
46Planlayın | CVE-2014-4650Kavram kanıtı | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which alpython · python · CWE-22 | Kritik9,8 | — | %24,7 | 20 Şub 2020 |
46Planlayın | CVE-2021-3177İstismar yok | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pythpython · python · CWE-120 | Kritik9,8 | — | %23,3 | 19 Oca 2021 |
45Planlayın | CVE-2018-1000802Kavram kanıtı | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Cpython · python · CWE-77 | Kritik9,8 | — | %20,1 | 18 Eyl 2018 |
43Planlayın | CVE-2016-0718İstismar yok | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docummozilla · firefox · CWE-119 | Kritik9,8 | — | %13,3 | 26 May 2016 |
43Planlayın | CVE-2014-3007İstismar yok | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharactpython · pillow · CWE-78 | Kritik10,0 | — | %11,6 | 27 Nis 2014 |
42Planlayın | CVE-2019-9636İstismar yok | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFpython · python | Kritik9,8 | — | %8,8 | 8 Mar 2019 |
42Planlayın | CVE-2020-27619İstismar yok | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.python · python | Kritik9,8 | — | %8,3 | 21 Eki 2020 |
41Planlayın | CVE-2019-12900İstismar yok | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Kritik9,8 | — | %8,0 | 19 Haz 2019 |
41Planlayın | CVE-2017-1000158İstismar yok | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting inpython · python · CWE-190 | Kritik9,8 | — | %7,9 | 17 Kas 2017 |
41Planlayın | CVE-2016-4009İstismar yok | Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have upython · pillow · CWE-119 | Kritik9,8 | — | %7,9 | 13 Nis 2016 |
41Planlayın | CVE-2021-29921İstismar yok | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.python · python | Kritik9,8 | — | %6,9 | 6 May 2021 |
41Planlayın | CVE-2022-37454İstismar yok | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers toextended keccak code package project · extended keccak code package · CWE-190 | Kritik9,8 | — | %5,8 | 21 Eki 2022 |
41Planlayın | CVE-2016-9063İstismar yok | An integer overflow during the parsing of XML using the Expat library.mozilla · firefox · CWE-190 | Kritik9,8 | — | %5,5 | 11 Haz 2018 |
41Planlayın | CVE-2019-10160İstismar yok | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7python · python · CWE-172 | Kritik9,8 | — | %5,2 | 7 Haz 2019 |
41Planlayın | CVE-2022-48565Kavram kanıtı | An XML External Entity (XXE) issue was discovered in Python through 3.9.1.python · python · CWE-611 | Kritik9,8 | — | %5,1 | 22 Ağu 2023 |
41Planlayın | CVE-2008-5031İstismar yok | Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large ipython · python · CWE-189 | Kritik10,0 | — | %3,0 | 10 Kas 2008 |
40Planlayın | CVE-2019-9948İstismar yok | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanipython · python · CWE-22 | Kritik9,1 | — | %11,8 | 23 Mar 2019 |
40Planlayın | CVE-2017-2810İstismar yok | An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.python · tablib | Kritik9,8 | — | %4,9 | 14 Haz 2017 |
40Planlayın | CVE-2018-20060İstismar yok | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diffpython · urllib3 | Kritik9,8 | — | %4,5 | 11 Ara 2018 |
40Planlayın | CVE-2020-13388İstismar yok | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.python · jw.util · CWE-78 | Kritik9,8 | — | %4,4 | 22 May 2020 |
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2016-218358Planlayın
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
YüksekCVSS 7,5Kavram kanıtıEPSS %95redhat · jboss enterprise application platform31 Ağu 2016
- CVE-2007-455947Planlayın
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot
KritikCVSS 9,8Kavram kanıtıEPSS %27python · python27 Ağu 2007
- CVE-2016-563647Planlayın
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all
KritikCVSS 9,8Kavram kanıtıEPSS %25python · python2 Eyl 2016
- CVE-2018-2503246Planlayın
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
YüksekCVSS 7,5Kavram kanıtıEPSS %52zlib · zlib25 Mar 2022
- CVE-2014-465046Planlayın
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al
KritikCVSS 9,8Kavram kanıtıEPSS %25python · python20 Şub 2020
- CVE-2021-317746Planlayın
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth
KritikCVSS 9,8İstismar yokEPSS %23python · python19 Oca 2021
- CVE-2018-100080245Planlayın
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C
KritikCVSS 9,8Kavram kanıtıEPSS %20python · python18 Eyl 2018
- CVE-2016-071843Planlayın
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum
KritikCVSS 9,8İstismar yokEPSS %13mozilla · firefox26 May 2016
- CVE-2014-300743Planlayın
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact
KritikCVSS 10,0İstismar yokEPSS %12python · pillow27 Nis 2014
- CVE-2019-963642Planlayın
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF
KritikCVSS 9,8İstismar yokEPSS %9python · python8 Mar 2019
- CVE-2020-2761942Planlayın
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
KritikCVSS 9,8İstismar yokEPSS %8python · python21 Eki 2020
- CVE-2019-1290041Planlayın
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
KritikCVSS 9,8İstismar yokEPSS %8bzip · bzip219 Haz 2019
- CVE-2017-100015841Planlayın
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in
KritikCVSS 9,8İstismar yokEPSS %8python · python17 Kas 2017
- CVE-2016-400941Planlayın
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u
KritikCVSS 9,8İstismar yokEPSS %8python · pillow13 Nis 2016
- CVE-2021-2992141Planlayın
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.
KritikCVSS 9,8İstismar yokEPSS %7python · python6 May 2021
- CVE-2022-3745441Planlayın
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to
KritikCVSS 9,8İstismar yokEPSS %6extended keccak code package project · extended keccak code package21 Eki 2022
- CVE-2016-906341Planlayın
An integer overflow during the parsing of XML using the Expat library.
KritikCVSS 9,8İstismar yokEPSS %5mozilla · firefox11 Haz 2018
- CVE-2019-1016041Planlayın
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7
KritikCVSS 9,8İstismar yokEPSS %5python · python7 Haz 2019
- CVE-2022-4856541Planlayın
An XML External Entity (XXE) issue was discovered in Python through 3.9.1.
KritikCVSS 9,8Kavram kanıtıEPSS %5python · python22 Ağu 2023
- CVE-2008-503141Planlayın
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i
KritikCVSS 10,0İstismar yokEPSS %3python · python10 Kas 2008
- CVE-2019-994840Planlayın
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani
KritikCVSS 9,1İstismar yokEPSS %12python · python23 Mar 2019
- CVE-2017-281040Planlayın
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.
KritikCVSS 9,8İstismar yokEPSS %5python · tablib14 Haz 2017
- CVE-2018-2006040Planlayın
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff
KritikCVSS 9,8İstismar yokEPSS %4python · urllib311 Ara 2018
- CVE-2020-1338840Planlayın
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.
KritikCVSS 9,8İstismar yokEPSS %4python · jw.util22 May 2020