Python

Python

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.14%
  • Veröffentlicht 27.11.2019 17:15:14
  • Zuletzt bearbeitet 21.11.2024 02:42:52

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

Exploit
  • EPSS 6.01%
  • Veröffentlicht 31.10.2019 21:15:13
  • Zuletzt bearbeitet 21.11.2024 04:44:10

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can ini...

  • EPSS 3.17%
  • Veröffentlicht 23.10.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:06

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (sp...

Medienbericht Exploit
  • EPSS 1.71%
  • Veröffentlicht 12.10.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:25

library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross applicatio...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 28.09.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:23

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_ti...

  • EPSS 0.91%
  • Veröffentlicht 06.09.2019 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:29:57

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 04.09.2019 06:15:10
  • Zuletzt bearbeitet 30.05.2025 20:15:23

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-r...

Exploit
  • EPSS 1.7%
  • Veröffentlicht 13.07.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:02:18

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a serv...

  • EPSS 0.16%
  • Veröffentlicht 08.07.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:24:52

The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it i...

  • EPSS 1.13%
  • Veröffentlicht 19.06.2019 23:15:09
  • Zuletzt bearbeitet 09.06.2025 16:15:29

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.