Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 910

redhat логотип

CVE-2010-2089

около 16 лет назад

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-2940

больше 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-2940

больше 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-2940

больше 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-2940

больше 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2008-5983

около 17 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-5983

около 17 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function ...

CVSS2: 6.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2010-2089

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

CVSS2: 4.3
11%
Средний
около 16 лет назад
nvd логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ...

CVSS2: 5
2%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-5983

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

CVSS2: 6.9
0%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5983

Untrusted search path vulnerability in the PySys_SetArgv API function ...

CVSS2: 6.9
0%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться