CVE-2024-3219
- EPSS 0.05%
- Veröffentlicht 29.07.2024 22:15:04
- Zuletzt bearbeitet 02.05.2025 23:15:15
The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of socket...
CVE-2024-5642
- EPSS 0.19%
- Veröffentlicht 27.06.2024 21:15:16
- Zuletzt bearbeitet 07.10.2025 17:15:32
CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL)...
CVE-2024-0397
- EPSS 0.42%
- Veröffentlicht 17.06.2024 16:15:10
- Zuletzt bearbeitet 03.11.2025 22:16:33
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as cer...
CVE-2024-4032
- EPSS 1.02%
- Veröffentlicht 17.06.2024 15:15:52
- Zuletzt bearbeitet 03.11.2025 22:18:33
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.I...
CVE-2024-4030
- EPSS 0.03%
- Veröffentlicht 07.05.2024 21:15:09
- Zuletzt bearbeitet 21.11.2024 09:42:03
On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alter...
CVE-2024-0450
- EPSS 0.15%
- Veröffentlicht 19.03.2024 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:16:34
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high...
CVE-2023-6597
- EPSS 0.08%
- Veröffentlicht 19.03.2024 16:15:08
- Zuletzt bearbeitet 03.11.2025 22:16:33
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related er...