Python

Python

126 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 11.89%
  • Veröffentlicht 20.02.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 02:10:38

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended...

  • EPSS 1.24%
  • Veröffentlicht 04.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:05

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

Exploit
  • EPSS 3.25%
  • Veröffentlicht 30.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:56

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicA...

  • EPSS 0.32%
  • Veröffentlicht 28.01.2020 19:15:17
  • Zuletzt bearbeitet 21.11.2024 05:38:41

In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's c...

  • EPSS 9.14%
  • Veröffentlicht 27.11.2019 17:15:14
  • Zuletzt bearbeitet 21.11.2024 02:42:52

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

Exploit
  • EPSS 3.67%
  • Veröffentlicht 31.10.2019 21:15:13
  • Zuletzt bearbeitet 21.11.2024 04:44:10

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can ini...

  • EPSS 3.17%
  • Veröffentlicht 23.10.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:06

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (sp...

Medienbericht Exploit
  • EPSS 1.08%
  • Veröffentlicht 12.10.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:25

library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross applicatio...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 28.09.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:23

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_ti...

  • EPSS 0.58%
  • Veröffentlicht 06.09.2019 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:29:57

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...