CVE-2014-4616
- EPSS 0.43%
- Published 24.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decod...
CVE-2017-9233
- EPSS 0.16%
- Published 25.07.2017 20:29:00
- Last modified 20.04.2025 01:37:25
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
CVE-2016-5699
- EPSS 11.63%
- Published 02.09.2016 14:59:07
- Last modified 12.04.2025 10:46:40
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
- EPSS 63.69%
- Published 02.09.2016 14:59:06
- Last modified 12.04.2025 10:46:40
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based bu...
CVE-2016-0772
- EPSS 13.18%
- Published 02.09.2016 14:59:00
- Last modified 12.04.2025 10:46:40
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network posi...
CVE-2016-2183
- EPSS 40.02%
- Published 01.09.2016 00:59:00
- Last modified 12.04.2025 10:46:40
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-4472
- EPSS 1.68%
- Published 30.06.2016 17:59:04
- Last modified 12.04.2025 10:46:40
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists ...
CVE-2016-3189
- EPSS 15.13%
- Published 30.06.2016 17:59:01
- Last modified 09.06.2025 16:15:25
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
CVE-2013-7440
- EPSS 0.36%
- Published 07.06.2016 18:59:00
- Last modified 12.04.2025 10:46:40
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
CVE-2016-0718
- EPSS 1.5%
- Published 26.05.2016 16:59:00
- Last modified 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.