CVE-2013-0340
- EPSS 0.05%
- Veröffentlicht 21.01.2014 18:55:09
- Zuletzt bearbeitet 25.11.2025 17:15:47
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests t...
CVE-2013-2099
- EPSS 4.07%
- Veröffentlicht 09.10.2013 14:53:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial ...
CVE-2013-4238
- EPSS 4.27%
- Veröffentlicht 18.08.2013 02:52:22
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof ar...
- EPSS 3.82%
- Veröffentlicht 05.10.2012 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that...
- EPSS 1.03%
- Veröffentlicht 05.10.2012 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU ...
CVE-2011-4944
- EPSS 0.03%
- Veröffentlicht 27.08.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.
CVE-2012-2135
- EPSS 1.62%
- Veröffentlicht 14.08.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of ser...
CVE-2012-0876
- EPSS 0.31%
- Veröffentlicht 03.07.2012 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...
CVE-2011-4940
- EPSS 0.23%
- Veröffentlicht 27.06.2012 10:18:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote a...
CVE-2011-1521
- EPSS 1%
- Veröffentlicht 24.05.2011 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (r...