Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 1 104

nvd логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-0391

больше 4 лет назад

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-02303

больше 4 лет назад

Уязвимость клиентской библиотеки FTP (File Transfer Protocol) интерпретатора языка программирования Python, позволяющая нарушителю выполнять SSRF-атаки

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2022-02302

больше 4 лет назад

Уязвимость модуля urllib.parse интерпретатора языка программирования Python, позволяющая нарушителю внедрить произвольные данные в ответ сервера

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qjw-vx62-3vqx

больше 4 лет назад

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2021-4189

больше 4 лет назад

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2021-9562

больше 4 лет назад

ELSA-2021-9562: python3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4399

больше 4 лет назад

ELSA-2021-4399: python3 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4057

почти 5 лет назад

ELSA-2021-4057: python3 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse modul ...

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-0391

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-02303

Уязвимость клиентской библиотеки FTP (File Transfer Protocol) интерпретатора языка программирования Python, позволяющая нарушителю выполнять SSRF-атаки

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-02302

Уязвимость модуля urllib.parse интерпретатора языка программирования Python, позволяющая нарушителю внедрить произвольные данные в ответ сервера

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4qjw-vx62-3vqx

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSS3: 5.9
36%
Средний
больше 4 лет назад
redhat логотип
CVE-2021-4189

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2021-9562

ELSA-2021-9562: python3 security update (IMPORTANT)

2%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2021-4399

ELSA-2021-4399: python3 security update (MODERATE)

2%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2021-4057

ELSA-2021-4057: python3 security update (MODERATE)

5%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться