İçeriğe atla
Noroxi

python kayıtları

python üreticisine ait 280 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,4
Pre-auth RCE
22
Düzeltme kaydı olan
%94,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

280 kayıt
  • CVE-2014-0224
    58Planlayın

    OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi

    YüksekCVSS 7,4SilahlaştırılmışEPSS %95

    openssl · openssl5 Haz 2014

  • CVE-2016-2183
    58Planlayın

    The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    YüksekCVSS 7,5Kavram kanıtıEPSS %95

    redhat · jboss enterprise application platform31 Ağu 2016

  • CVE-2007-4559
    47Planlayın

    Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remot

    KritikCVSS 9,8Kavram kanıtıEPSS %27

    python · python27 Ağu 2007

  • CVE-2016-5636
    47Planlayın

    Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 all

    KritikCVSS 9,8Kavram kanıtıEPSS %25

    python · python2 Eyl 2016

  • CVE-2018-25032
    46Planlayın

    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    YüksekCVSS 7,5Kavram kanıtıEPSS %52

    zlib · zlib25 Mar 2022

  • CVE-2014-4650
    46Planlayın

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which al

    KritikCVSS 9,8Kavram kanıtıEPSS %25

    python · python20 Şub 2020

  • CVE-2021-3177
    46Planlayın

    Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Pyth

    KritikCVSS 9,8İstismar yokEPSS %23

    python · python19 Oca 2021

  • CVE-2018-1000802
    45Planlayın

    Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('C

    KritikCVSS 9,8Kavram kanıtıEPSS %20

    python · python18 Eyl 2018

  • CVE-2016-0718
    43Planlayın

    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum

    KritikCVSS 9,8İstismar yokEPSS %13

    mozilla · firefox26 May 2016

  • CVE-2014-3007
    43Planlayın

    Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharact

    KritikCVSS 10,0İstismar yokEPSS %12

    python · pillow27 Nis 2014

  • CVE-2019-9636
    42Planlayın

    Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NF

    KritikCVSS 9,8İstismar yokEPSS %9

    python · python8 Mar 2019

  • CVE-2020-27619
    42Planlayın

    In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

    KritikCVSS 9,8İstismar yokEPSS %8

    python · python21 Eki 2020

  • CVE-2019-12900
    41Planlayın

    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

    KritikCVSS 9,8İstismar yokEPSS %8

    bzip · bzip219 Haz 2019

  • CVE-2017-1000158
    41Planlayın

    CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in

    KritikCVSS 9,8İstismar yokEPSS %8

    python · python17 Kas 2017

  • CVE-2016-4009
    41Planlayın

    Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have u

    KritikCVSS 9,8İstismar yokEPSS %8

    python · pillow13 Nis 2016

  • CVE-2021-29921
    41Planlayın

    In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.

    KritikCVSS 9,8İstismar yokEPSS %7

    python · python6 May 2021

  • CVE-2022-37454
    41Planlayın

    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to

    KritikCVSS 9,8İstismar yokEPSS %6

    extended keccak code package project · extended keccak code package21 Eki 2022

  • CVE-2016-9063
    41Planlayın

    An integer overflow during the parsing of XML using the Expat library.

    KritikCVSS 9,8İstismar yokEPSS %5

    mozilla · firefox11 Haz 2018

  • CVE-2019-10160
    41Planlayın

    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7

    KritikCVSS 9,8İstismar yokEPSS %5

    python · python7 Haz 2019

  • CVE-2022-48565
    41Planlayın

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    python · python22 Ağu 2023

  • CVE-2008-5031
    41Planlayın

    Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large i

    KritikCVSS 10,0İstismar yokEPSS %3

    python · python10 Kas 2008

  • CVE-2019-9948
    40Planlayın

    urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechani

    KritikCVSS 9,1İstismar yokEPSS %12

    python · python23 Mar 2019

  • CVE-2017-2810
    40Planlayın

    An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4.

    KritikCVSS 9,8İstismar yokEPSS %5

    python · tablib14 Haz 2017

  • CVE-2018-20060
    40Planlayın

    urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff

    KritikCVSS 9,8İstismar yokEPSS %4

    python · urllib311 Ara 2018

  • CVE-2020-13388
    40Planlayın

    An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python.

    KritikCVSS 9,8İstismar yokEPSS %4

    python · jw.util22 May 2020