CVE-2023-6507
- EPSS 0.1%
- Veröffentlicht 08.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:59
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]...
CVE-2023-40217
- EPSS 0.58%
- Veröffentlicht 25.08.2023 01:15:09
- Zuletzt bearbeitet 03.11.2025 22:16:25
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, rec...
CVE-2023-41105
- EPSS 0.37%
- Veröffentlicht 23.08.2023 07:15:08
- Zuletzt bearbeitet 21.11.2024 08:20:35
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejec...
CVE-2022-48565
- EPSS 7.27%
- Veröffentlicht 22.08.2023 19:16:32
- Zuletzt bearbeitet 21.11.2024 07:33:30
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
CVE-2022-48566
- EPSS 0.1%
- Veröffentlicht 22.08.2023 19:16:32
- Zuletzt bearbeitet 21.11.2024 07:33:31
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
CVE-2022-48560
- EPSS 0.19%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 21.11.2024 07:33:30
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
CVE-2022-48564
- EPSS 0.1%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 21.11.2024 07:33:30
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
CVE-2023-38898
- EPSS 0.38%
- Veröffentlicht 15.08.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:14:24
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.1...
CVE-2023-36632
- EPSS 0.11%
- Veröffentlicht 25.06.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:10:07
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from...
CVE-2023-33595
- EPSS 0.06%
- Veröffentlicht 07.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:45
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.