Nltk

Nltk

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.9%
  • Veröffentlicht 04.03.2026 18:25:30
  • Zuletzt bearbeitet 15.07.2026 02:17:57

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properl...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 18.02.2026 17:45:17
  • Zuletzt bearbeitet 15.07.2026 02:17:16

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attacke...

  • EPSS 1.35%
  • Veröffentlicht 27.06.2024 22:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

Exploit
  • EPSS 1.46%
  • Veröffentlicht 04.01.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:36

nltk is vulnerable to Inefficient Regular Expression Complexity

Exploit
  • EPSS 2.67%
  • Veröffentlicht 23.12.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:56

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReD...

Exploit
  • EPSS 1.7%
  • Veröffentlicht 27.09.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:33

nltk is vulnerable to Inefficient Regular Expression Complexity

Exploit
  • EPSS 5.67%
  • Veröffentlicht 22.08.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:16

NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.