Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.93.103.113.123.1320202021202220232024202520262027202820292030

Недавние уязвимости Python

Количество 879

ubuntu логотип

CVE-2011-4944

почти 13 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2012-2135

почти 13 лет назад

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-2135

почти 13 лет назад

The utf-16 decoder in Python 3.1 through 3.3 does not update the align ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-2135

почти 13 лет назад

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-0876

около 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0876

около 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0876

около 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4940

около 13 лет назад

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2011-4940

около 13 лет назад

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPSe ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4940

около 13 лет назад

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2011-4944

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

CVSS2: 1.9
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2135

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

CVSS2: 6.4
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2135

The utf-16 decoder in Python 3.1 through 3.3 does not update the align ...

CVSS2: 6.4
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2135

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

CVSS2: 6.4
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0876

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

CVSS2: 4.3
0%
Низкий
около 13 лет назад
debian логотип
CVE-2012-0876

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values ...

CVSS2: 4.3
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2012-0876

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

CVSS2: 4.3
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4940

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
1%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4940

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPSe ...

CVSS2: 2.6
1%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4940

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
1%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться