Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.93.103.113.123.1320202021202220232024202520262027202820292030

Недавние уязвимости Python

Количество 879

redhat логотип

CVE-2019-17514

почти 6 лет назад

library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross application domains, and thus it is likely that security-relevant code elsewhere is affected. This issue is not a Python implementation bug, and there are no reports that NMR researchers were specifically relying on library/glob.html. In other words, because the older documentation stated "finds all the pathnames matching a specified pattern according to the rules used by the Unix shell," one might have incorrectly inferred that the sorting that occurs in a Unix shell also occurred for glob.glob. There is a workaround in newer versions of Willoughby nmr-data_compilation-p2.py and nmr-data_compilation-p3.py, which call sort() directly.

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2205-1

почти 6 лет назад

Security update for expat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2204-1

почти 6 лет назад

Security update for expat

EPSS: Низкий
nvd логотип

CVE-2019-16935

почти 6 лет назад

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-16935

почти 6 лет назад

The documentation XML-RPC server in Python through 2.7.16, 3.x through ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-16935

почти 6 лет назад

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2440-1

почти 6 лет назад

Security update for expat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2429-1

почти 6 лет назад

Security update for expat

EPSS: Низкий
redhat логотип

CVE-2019-16935

почти 6 лет назад

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2020-01347

почти 6 лет назад

Уязвимость модуля электронной почты интерпретатора языка программирования Python, позволяющая нарушителю принимать электронные сообщения от адресов электронной почты, которые должны быть отклонены

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2019-17514

library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross application domains, and thus it is likely that security-relevant code elsewhere is affected. This issue is not a Python implementation bug, and there are no reports that NMR researchers were specifically relying on library/glob.html. In other words, because the older documentation stated "finds all the pathnames matching a specified pattern according to the rules used by the Unix shell," one might have incorrectly inferred that the sorting that occurs in a Unix shell also occurred for glob.glob. There is a workaround in newer versions of Willoughby nmr-data_compilation-p2.py and nmr-data_compilation-p3.py, which call sort() directly.

1%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2205-1

Security update for expat

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2204-1

Security update for expat

0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-16935

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-16935

The documentation XML-RPC server in Python through 2.7.16, 3.x through ...

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-16935

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2440-1

Security update for expat

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2429-1

Security update for expat

0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-16935

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
fstec логотип
BDU:2020-01347

Уязвимость модуля электронной почты интерпретатора языка программирования Python, позволяющая нарушителю принимать электронные сообщения от адресов электронной почты, которые должны быть отклонены

CVSS3: 7.5
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться