Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 915

debian логотип

CVE-2021-3426

больше 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who d ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2021-3426

больше 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
EPSS: Низкий
fstec логотип

BDU:2021-03708

больше 4 лет назад

Уязвимость модуля pandoc языка программирования Python, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1621-1

больше 4 лет назад

Security update for python3

EPSS: Низкий
github логотип

GHSA-9gg6-cm3f-wf38

больше 4 лет назад

Incorrect Calculation and Use of Insufficiently Random Values in Python

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1557-1

больше 4 лет назад

Security update for python3

EPSS: Низкий
nvd логотип

CVE-2021-32052

почти 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-32052

почти 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 ( ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-32052

почти 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-29921

почти 5 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who d ...

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2021-03708

Уязвимость модуля pandoc языка программирования Python, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1621-1

Security update for python3

1%
Низкий
больше 4 лет назад
github логотип
GHSA-9gg6-cm3f-wf38

Incorrect Calculation and Use of Insufficiently Random Values in Python

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1557-1

Security update for python3

0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
2%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 ( ...

CVSS3: 6.1
2%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-29921

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
2%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться