CVE-2020-26116
- EPSS 0.9%
- Veröffentlicht 27.09.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:19:16
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first ar...
CVE-2020-15801
- EPSS 0.62%
- Veröffentlicht 17.07.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:12
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
CVE-2019-20907
- EPSS 0.32%
- Veröffentlicht 13.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:39
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-15523
- EPSS 0.12%
- Veröffentlicht 04.07.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:41
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use a...
CVE-2020-14422
- EPSS 0.7%
- Veröffentlicht 18.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:13
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary...
CVE-2013-1753
- EPSS 0.46%
- Veröffentlicht 11.03.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:50:19
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
CVE-2014-4650
- EPSS 6.02%
- Veröffentlicht 20.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 02:10:38
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended...
CVE-2019-9674
- EPSS 1.16%
- Veröffentlicht 04.02.2020 15:15:11
- Zuletzt bearbeitet 31.12.2025 00:55:36
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
CVE-2020-8492
- EPSS 3.51%
- Veröffentlicht 30.01.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:56
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicA...
CVE-2020-8315
- EPSS 0.32%
- Veröffentlicht 28.01.2020 19:15:17
- Zuletzt bearbeitet 21.11.2024 05:38:41
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's c...