Python

Python

126 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.9%
  • Published 25.09.2018 00:29:00
  • Last modified 21.11.2024 03:49:30

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions ...

  • EPSS 23.2%
  • Published 18.09.2018 17:29:00
  • Last modified 21.11.2024 03:40:23

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service...

  • EPSS 0.93%
  • Published 19.06.2018 12:29:00
  • Last modified 21.11.2024 03:59:05

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

Exploit
  • EPSS 0.96%
  • Published 18.06.2018 14:29:00
  • Last modified 21.11.2024 03:59:05

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

  • EPSS 1.46%
  • Published 11.06.2018 21:29:00
  • Last modified 21.11.2024 03:00:31

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

  • EPSS 0.07%
  • Published 07.03.2018 14:29:00
  • Last modified 21.11.2024 03:39:40

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears t...

  • EPSS 0.44%
  • Published 01.03.2018 05:29:00
  • Last modified 21.11.2024 03:19:34

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the v...

  • EPSS 1.46%
  • Published 08.02.2018 17:29:00
  • Last modified 21.11.2024 03:39:28

Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The...

  • EPSS 0.65%
  • Published 14.12.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a softwa...

  • EPSS 2.12%
  • Published 17.11.2017 05:29:00
  • Last modified 20.04.2025 01:37:25

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)