Python

Python

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 27.08.2012 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

  • EPSS 1.37%
  • Veröffentlicht 14.08.2012 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of ser...

  • EPSS 0.31%
  • Veröffentlicht 03.07.2012 19:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...

  • EPSS 0.24%
  • Veröffentlicht 27.06.2012 10:18:36
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote a...

  • EPSS 1%
  • Veröffentlicht 24.05.2011 23:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (r...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 09.05.2011 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

  • EPSS 1.15%
  • Veröffentlicht 19.10.2010 20:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, whic...

  • EPSS 2.08%
  • Veröffentlicht 19.10.2010 20:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept f...

  • EPSS 2.61%
  • Veröffentlicht 27.05.2010 19:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer underflow in the rgbimg module in Python 2.5 allows remote attackers to cause a denial of service (application crash) via a large ZSIZE value in a black-and-white (aka B/W) RGB image that triggers an invalid pointer dereference.

  • EPSS 3.79%
  • Veröffentlicht 27.05.2010 19:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-...