Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 924

suse-cvrf логотип

SUSE-SU-2020:0750-1

около 6 лет назад

Security update for python36

EPSS: Низкий
nvd логотип

CVE-2013-1753

около 6 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2013-1753

около 6 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 an ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-1753

около 6 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14306-1

около 6 лет назад

Security update for python

EPSS: Низкий
redhat логотип

CVE-2020-8492

около 6 лет назад

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2014-4650

около 6 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2014-4650

около 6 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-4650

около 6 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2020-26116

около 6 лет назад

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2020:0750-1

Security update for python36

3%
Низкий
около 6 лет назад
nvd логотип
CVE-2013-1753

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2013-1753

The gzip_decode function in the xmlrpc client library in Python 3.4 an ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2013-1753

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:14306-1

Security update for python

4%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-8492

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

CVSS3: 6.5
4%
Низкий
около 6 лет назад
nvd логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
6%
Низкий
около 6 лет назад
debian логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ...

CVSS3: 9.8
6%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
6%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-26116

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 6.5
1%
Низкий
около 6 лет назад

Уязвимостей на страницу


Поделиться