pyyaml kayıtları
pyyaml üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-502 Deserialization of Untrusted Data2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-14343Kavram kanıtı | A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it propyyaml · pyyaml · CWE-20 | Kritik9,8 | — | %6,0 | 9 Şub 2021 |
41Planlayın | CVE-2017-18342İstismar yok | In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data.pyyaml · pyyaml · CWE-502 | Kritik9,8 | — | %5,7 | 27 Haz 2018 |
41Planlayın | CVE-2020-1747İstismar yok | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it ppyyaml · pyyaml · CWE-20 | Kritik9,8 | — | %5,4 | 24 Mar 2020 |
41Planlayın | CVE-2019-20477İstismar yok | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popyyaml · pyyaml · CWE-502 | Kritik9,8 | — | %5,1 | 19 Şub 2020 |
30İzleyin | CVE-2014-2525İstismar yok | Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to executpyyaml · libyaml · CWE-119 | Orta6,8 | — | %8,8 | 28 Mar 2014 |
29İzleyin | CVE-2013-6393İstismar yok | The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to causpyyaml · libyaml · CWE-119 | Orta6,8 | — | %7,4 | 6 Şub 2014 |
24İzleyin | CVE-2014-9130İstismar yok | scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to causepyyaml · libyaml · CWE-20 | Orta5,0 | — | %13,2 | 8 Ara 2014 |
- CVE-2020-1434341Planlayın
A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it pro
KritikCVSS 9,8Kavram kanıtıEPSS %6pyyaml · pyyaml9 Şub 2021
- CVE-2017-1834241Planlayın
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data.
KritikCVSS 9,8İstismar yokEPSS %6pyyaml · pyyaml27 Haz 2018
- CVE-2020-174741Planlayın
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it p
KritikCVSS 9,8İstismar yokEPSS %5pyyaml · pyyaml24 Mar 2020
- CVE-2019-2047741Planlayın
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Po
KritikCVSS 9,8İstismar yokEPSS %5pyyaml · pyyaml19 Şub 2020
- CVE-2014-252530İzleyin
Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execut
OrtaCVSS 6,8İstismar yokEPSS %9pyyaml · libyaml28 Mar 2014
- CVE-2013-639329İzleyin
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to caus
OrtaCVSS 6,8İstismar yokEPSS %7pyyaml · libyaml6 Şub 2014
- CVE-2014-913024İzleyin
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause
OrtaCVSS 5,0İstismar yokEPSS %13pyyaml · libyaml8 Ara 2014