Python

Python

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 25.07.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

Exploit
  • EPSS 41.71%
  • Veröffentlicht 02.09.2016 14:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

  • EPSS 45.12%
  • Veröffentlicht 02.09.2016 14:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based bu...

  • EPSS 7.64%
  • Veröffentlicht 02.09.2016 14:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network posi...

Medienbericht
  • EPSS 37.75%
  • Veröffentlicht 01.09.2016 00:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...

  • EPSS 2.27%
  • Veröffentlicht 30.06.2016 17:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists ...

  • EPSS 23.71%
  • Veröffentlicht 30.06.2016 17:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

  • EPSS 0.36%
  • Veröffentlicht 07.06.2016 18:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

  • EPSS 2.83%
  • Veröffentlicht 26.05.2016 16:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

  • EPSS 0.15%
  • Veröffentlicht 06.10.2015 01:59:27
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a...