CVE-2016-9063
- EPSS 2.42%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:31
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2018-1000117
- EPSS 0.07%
- Veröffentlicht 07.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:40
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears t...
CVE-2017-18207
- EPSS 0.78%
- Veröffentlicht 01.03.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:34
The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the v...
CVE-2018-1000030
- EPSS 1.58%
- Veröffentlicht 08.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:28
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The...
CVE-2017-17522
- EPSS 0.65%
- Veröffentlicht 14.12.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a softwa...
CVE-2017-1000158
- EPSS 3.72%
- Veröffentlicht 17.11.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
CVE-2014-4616
- EPSS 0.56%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decod...
CVE-2017-9233
- EPSS 0.25%
- Veröffentlicht 25.07.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
CVE-2016-5699
- EPSS 41.71%
- Veröffentlicht 02.09.2016 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
- EPSS 63.69%
- Veröffentlicht 02.09.2016 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based bu...