Python

Python

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 19.04.2023 00:15:07
  • Zuletzt bearbeitet 17.12.2025 22:15:57

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protect...

Exploit
  • EPSS 1.44%
  • Veröffentlicht 17.02.2023 15:15:12
  • Zuletzt bearbeitet 03.11.2025 22:16:05

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 09.11.2022 07:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:01

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead t...

  • EPSS 0.03%
  • Veröffentlicht 07.11.2022 00:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:00

Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized ...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 21.10.2022 06:15:09
  • Zuletzt bearbeitet 08.05.2025 15:15:47

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function int...

  • EPSS 0.31%
  • Veröffentlicht 09.09.2022 14:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:46

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes()...

  • EPSS 0.73%
  • Veröffentlicht 24.08.2022 16:15:09
  • Zuletzt bearbeitet 17.12.2025 22:15:57

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious ...

  • EPSS 1.4%
  • Veröffentlicht 23.08.2022 01:15:07
  • Zuletzt bearbeitet 17.12.2025 22:15:56

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 16.06.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 03:22:31

A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been di...

Exploit
  • EPSS 0.91%
  • Veröffentlicht 13.04.2022 16:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:43

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untruste...