CVE-2016-1000110
- EPSS 10.14%
- Veröffentlicht 27.11.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 02:42:52
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
CVE-2019-5010
- EPSS 6.01%
- Veröffentlicht 31.10.2019 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:10
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can ini...
CVE-2019-18348
- EPSS 3.17%
- Veröffentlicht 23.10.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:06
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (sp...
CVE-2019-17514
- EPSS 1.71%
- Veröffentlicht 12.10.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:25
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross applicatio...
CVE-2019-16935
- EPSS 1.72%
- Veröffentlicht 28.09.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:23
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_ti...
CVE-2019-16056
- EPSS 0.91%
- Veröffentlicht 06.09.2019 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:29:57
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...
CVE-2019-15903
- EPSS 0.2%
- Veröffentlicht 04.09.2019 06:15:10
- Zuletzt bearbeitet 30.05.2025 20:15:23
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-r...
CVE-2018-20852
- EPSS 1.7%
- Veröffentlicht 13.07.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:02:18
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a serv...
CVE-2019-13404
- EPSS 0.16%
- Veröffentlicht 08.07.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:24:52
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it i...
CVE-2019-12900
- EPSS 1.13%
- Veröffentlicht 19.06.2019 23:15:09
- Zuletzt bearbeitet 09.06.2025 16:15:29
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.