CVE-2008-2316
- EPSS 1.69%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to "partial hashlib hashing of data exceeding 4GB."
CVE-2008-3142
- EPSS 1.65%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicod...
CVE-2008-3143
- EPSS 1.55%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c...
- EPSS 2.99%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer overflows in the PyOS_vsnprintf function in Python/mysnprintf.c in Python 2.5.2 and earlier allow context-dependent attackers to cause a denial of service (memory corruption) or have unspecified other impact via crafted input to stri...
CVE-2008-1679
- EPSS 0.44%
- Veröffentlicht 22.04.2008 04:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows. NOTE: this issue i...
CVE-2008-1887
- EPSS 2.39%
- Veröffentlicht 18.04.2008 17:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when asse...
CVE-2008-1721
- EPSS 28.41%
- Veröffentlicht 10.04.2008 19:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
CVE-2007-4965
- EPSS 5.03%
- Veröffentlicht 18.09.2007 22:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) t...
CVE-2007-4559
- EPSS 90.19%
- Veröffentlicht 28.08.2007 01:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related ...
- EPSS 13.74%
- Veröffentlicht 16.04.2007 22:19:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown m...