CVE-2018-1000802
- EPSS 26.49%
- Veröffentlicht 18.09.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:23
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service...
CVE-2018-1061
- EPSS 1.78%
- Veröffentlicht 19.06.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
CVE-2018-1060
- EPSS 1.04%
- Veröffentlicht 18.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
CVE-2016-9063
- EPSS 2.71%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:31
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2018-1000117
- EPSS 0.05%
- Veröffentlicht 07.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:40
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears t...
CVE-2017-18207
- EPSS 0.57%
- Veröffentlicht 01.03.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:34
The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the v...
CVE-2018-1000030
- EPSS 1.27%
- Veröffentlicht 08.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:28
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The...
CVE-2017-17522
- EPSS 0.65%
- Veröffentlicht 14.12.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a softwa...
CVE-2017-1000158
- EPSS 3.59%
- Veröffentlicht 17.11.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
CVE-2014-4616
- EPSS 0.38%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decod...