- EPSS 2.99%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in the PyOS_vsnprintf function in Python/mysnprintf.c in Python 2.5.2 and earlier allow context-dependent attackers to cause a denial of service (memory corruption) or have unspecified other impact via crafted input to stri...
CVE-2008-1679
- EPSS 0.44%
- Veröffentlicht 22.04.2008 04:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows. NOTE: this issue i...
CVE-2008-1887
- EPSS 2.75%
- Veröffentlicht 18.04.2008 17:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when asse...
CVE-2008-1721
- EPSS 31.08%
- Veröffentlicht 10.04.2008 19:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
CVE-2007-4965
- EPSS 4.34%
- Veröffentlicht 18.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) t...
CVE-2007-4559
- EPSS 90.58%
- Veröffentlicht 28.08.2007 01:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related ...
- EPSS 13.43%
- Veröffentlicht 16.04.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown m...
CVE-2006-4980
- EPSS 1.06%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the repr function in Python 2.3 through 2.6 before 20060822 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via crafted wide character UTF-32/UCS-4 strings to certain scripts.
CVE-2006-1542
- EPSS 0.21%
- Veröffentlicht 30.03.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory tha...
CVE-2005-0089
- EPSS 9.11%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of ...