Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 1 104

github логотип

GHSA-942q-qwfh-7rjq

больше 4 лет назад

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.

EPSS: Низкий
rocky логотип

RLSA-2022:1642

больше 4 лет назад

Important: zlib security update

EPSS: Средний
oracle-oval логотип

ELSA-2022-1642

больше 4 лет назад

ELSA-2022-1642: zlib security update (IMPORTANT)

EPSS: Средний
github логотип

GHSA-wvcr-2gc8-63gg

больше 4 лет назад

In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
fstec логотип

BDU:2022-03962

больше 4 лет назад

Уязвимость модуля mailcap интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольную команду

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1062-1

больше 4 лет назад

Security update for zlib

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2022:14929-1

больше 4 лет назад

Security update for zlib

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-942q-qwfh-7rjq

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.

5%
Низкий
больше 4 лет назад
rocky логотип
RLSA-2022:1642

Important: zlib security update

52%
Средний
больше 4 лет назад
oracle-oval логотип
ELSA-2022-1642

ELSA-2022-1642: zlib security update (IMPORTANT)

52%
Средний
больше 4 лет назад
github логотип
GHSA-wvcr-2gc8-63gg

In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
nvd логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
debian логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-03962

Уязвимость модуля mailcap интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольную команду

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:1062-1

Security update for zlib

52%
Средний
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:14929-1

Security update for zlib

52%
Средний
больше 4 лет назад

Уязвимостей на страницу


Поделиться