CVE-2015-5652
- EPSS 0.15%
- Published 06.10.2015 01:59:27
- Last modified 12.04.2025 10:46:40
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a...
CVE-2015-1283
- EPSS 0.63%
- Published 23.07.2015 00:59:12
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspec...
CVE-2014-9365
- EPSS 2.04%
- Published 12.12.2014 11:59:07
- Last modified 12.04.2025 10:46:40
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify tha...
CVE-2014-2667
- EPSS 0.05%
- Published 16.11.2014 01:59:01
- Last modified 12.04.2025 10:46:40
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulne...
CVE-2014-7185
- EPSS 0.66%
- Published 08.10.2014 17:55:05
- Last modified 12.04.2025 10:46:40
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
CVE-2014-0224
- EPSS 92.69%
- Published 05.06.2014 21:55:07
- Last modified 12.04.2025 10:46:40
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL...
CVE-2013-7040
- EPSS 0.56%
- Published 19.05.2014 14:55:09
- Last modified 12.04.2025 10:46:40
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attack...
CVE-2013-7338
- EPSS 5.21%
- Published 22.04.2014 14:23:34
- Last modified 12.04.2025 10:46:40
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, ...
CVE-2014-1912
- EPSS 32.07%
- Published 01.03.2014 00:55:05
- Last modified 12.04.2025 10:46:40
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
CVE-2013-0340
- EPSS 0.04%
- Published 21.01.2014 18:55:09
- Last modified 11.04.2025 00:51:21
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to i...