Python Software Foundation kayıtları
python software foundation üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2024-12254İstismar yok | Unbounded memory buffering in SelectorSocketTransport.writelines()python software foundation · cpython · CWE-400 | Yüksek8,7 | — | %1,9 | 6 Ara 2024 |
34İzleyin | CVE-2024-8088İstismar yok | Infinite loop when iterating over zip archive entry names from zipfile.Pathpython software foundation · cpython · CWE-835 | Yüksek8,7 | — | %1,3 | 22 Ağu 2024 |
31İzleyin | CVE-2007-1657Kavram kanıtı | Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to exepython software foundation · python | Yüksek7,5 | — | %4,7 | 23 Mar 2007 |
31İzleyin | CVE-2023-6597İstismar yok | An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and pripython software foundation · cpython | Yüksek7,8 | — | %0,3 | 19 Mar 2024 |
29İzleyin | CVE-2024-0397İstismar yok | Memory race condition in ssl.SSLContext certificate store methodspython software foundation · cpython · CWE-362 | Yüksek7,4 | — | %0,8 | 17 Haz 2024 |
28İzleyin | CVE-2008-4108İstismar yok | Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files vipython software foundation · python · CWE-59 | Yüksek7,2 | — | %0,4 | 18 Eyl 2008 |
25İzleyin | CVE-2024-11168İstismar yok | Improper validation of IPv6 and IPvFuture addressespython software foundation · cpython · CWE-918 | Orta6,3 | — | %0,7 | 12 Kas 2024 |
21İzleyin | CVE-2024-21503İstismar yok | Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_eCWE-1333 | Orta5,3 | — | %1,0 | 19 Mar 2024 |
17İzleyin | CVE-2008-0299İstismar yok | common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session python software foundation · paramiko | Orta4,3 | — | %1,6 | 16 Oca 2008 |
- CVE-2024-1225435İzleyin
Unbounded memory buffering in SelectorSocketTransport.writelines()
YüksekCVSS 8,7İstismar yokEPSS %2python software foundation · cpython6 Ara 2024
- CVE-2024-808834İzleyin
Infinite loop when iterating over zip archive entry names from zipfile.Path
YüksekCVSS 8,7İstismar yokEPSS %1python software foundation · cpython22 Ağu 2024
- CVE-2007-165731İzleyin
Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to exe
YüksekCVSS 7,5Kavram kanıtıEPSS %5python software foundation · python23 Mar 2007
- CVE-2023-659731İzleyin
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and pri
YüksekCVSS 7,8İstismar yokEPSS %0python software foundation · cpython19 Mar 2024
- CVE-2024-039729İzleyin
Memory race condition in ssl.SSLContext certificate store methods
YüksekCVSS 7,4İstismar yokEPSS %1python software foundation · cpython17 Haz 2024
- CVE-2008-410828İzleyin
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files vi
YüksekCVSS 7,2İstismar yokEPSS %0python software foundation · python18 Eyl 2008
- CVE-2024-1116825İzleyin
Improper validation of IPv6 and IPvFuture addresses
OrtaCVSS 6,3İstismar yokEPSS %1python software foundation · cpython12 Kas 2024
- CVE-2024-2150321İzleyin
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_e
OrtaCVSS 5,3İstismar yokEPSS %119 Mar 2024
- CVE-2008-029917İzleyin
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session
OrtaCVSS 4,3İstismar yokEPSS %2python software foundation · paramiko16 Oca 2008