Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.93.103.113.123.1320202021202220232024202520262027202820292030

Недавние уязвимости Python

Количество 879

suse-cvrf логотип

SUSE-SU-2017:0719-1

больше 8 лет назад

Security update for java-1_7_1-ibm

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2017:0716-1

больше 8 лет назад

Security update for java-1_7_0-ibm

EPSS: Средний
redhat логотип

CVE-2016-9063

почти 9 лет назад

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-5699

почти 9 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2016-5699

почти 9 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function ...

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2016-5636

почти 9 лет назад

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-5636

почти 9 лет назад

Integer overflow in the get_data function in zipimport.c in CPython (a ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2016-0772

почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-0772

почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-0772

почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2017:0719-1

Security update for java-1_7_1-ibm

31%
Средний
больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:0716-1

Security update for java-1_7_0-ibm

31%
Средний
больше 8 лет назад
redhat логотип
CVE-2016-9063

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-5699

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CVSS3: 6.1
11%
Средний
почти 9 лет назад
debian логотип
CVE-2016-5699

CRLF injection vulnerability in the HTTPConnection.putheader function ...

CVSS3: 6.1
11%
Средний
почти 9 лет назад
nvd логотип
CVE-2016-5636

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.

CVSS3: 9.8
66%
Средний
почти 9 лет назад
debian логотип
CVE-2016-5636

Integer overflow in the get_data function in zipimport.c in CPython (a ...

CVSS3: 9.8
66%
Средний
почти 9 лет назад
nvd логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
7%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

CVSS3: 6.5
7%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
7%
Низкий
почти 9 лет назад

Уязвимостей на страницу


Поделиться