Python — высокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.
Релизный цикл, информация об уязвимостях
График релизов
Количество 915
SUSE-RU-2020:0775-1
Recommended update for python-botocore
SUSE-SU-2020:0750-1
Security update for python36
CVE-2013-1753
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
CVE-2013-1753
The gzip_decode function in the xmlrpc client library in Python 3.4 an ...
CVE-2013-1753
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
SUSE-SU-2020:14306-1
Security update for python
CVE-2020-8492
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
CVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
CVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ...
CVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
SUSE-RU-2020:0775-1 Recommended update for python-botocore | 1% Низкий | почти 6 лет назад | ||
SUSE-SU-2020:0750-1 Security update for python36 | 3% Низкий | почти 6 лет назад | ||
CVE-2013-1753 The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2013-1753 The gzip_decode function in the xmlrpc client library in Python 3.4 an ... | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
CVE-2013-1753 The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request. | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
SUSE-SU-2020:14306-1 Security update for python | 4% Низкий | почти 6 лет назад | ||
CVE-2020-8492 Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking. | CVSS3: 6.5 | 4% Низкий | почти 6 лет назад | |
CVE-2014-4650 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator. | CVSS3: 9.8 | 6% Низкий | почти 6 лет назад | |
CVE-2014-4650 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ... | CVSS3: 9.8 | 6% Низкий | почти 6 лет назад | |
CVE-2014-4650 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator. | CVSS3: 9.8 | 6% Низкий | почти 6 лет назад |
Уязвимостей на страницу