CVE-2015-5652
- EPSS 0.15%
- Veröffentlicht 06.10.2015 01:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a...
CVE-2015-1283
- EPSS 0.63%
- Veröffentlicht 23.07.2015 00:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspec...
CVE-2014-9365
- EPSS 2.04%
- Veröffentlicht 12.12.2014 11:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify tha...
CVE-2014-2667
- EPSS 0.05%
- Veröffentlicht 16.11.2014 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulne...
CVE-2014-7185
- EPSS 0.66%
- Veröffentlicht 08.10.2014 17:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
CVE-2014-0224
- EPSS 92.69%
- Veröffentlicht 05.06.2014 21:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL...
CVE-2013-7040
- EPSS 0.56%
- Veröffentlicht 19.05.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attack...
CVE-2013-7338
- EPSS 5.21%
- Veröffentlicht 22.04.2014 14:23:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, ...
CVE-2014-1912
- EPSS 32.07%
- Veröffentlicht 01.03.2014 00:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
CVE-2013-0340
- EPSS 0.04%
- Veröffentlicht 21.01.2014 18:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to i...