Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.93.103.113.123.1320202021202220232024202520262027202820292030

Недавние уязвимости Python

Количество 880

redhat логотип

CVE-2006-1542

почти 20 лет назад

Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.

EPSS: Низкий
nvd логотип

CVE-2005-0089

больше 20 лет назад

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-0089

больше 20 лет назад

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0089

больше 20 лет назад

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2005-0089

больше 20 лет назад

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

EPSS: Низкий
nvd логотип

CVE-2004-0150

больше 21 года назад

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2004-0150

больше 21 года назад

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2 ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1119

почти 23 года назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2002-1119

почти 23 года назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary f ...

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2002-1119

около 23 лет назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2006-1542

Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.

0%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-0089

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0089

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, ...

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0089

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-0089

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

10%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-0150

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.

CVSS2: 7.5
9%
Низкий
больше 21 года назад
debian логотип
CVE-2004-0150

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2 ...

CVSS2: 7.5
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2002-1119

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

CVSS2: 4.6
0%
Низкий
почти 23 года назад
debian логотип
CVE-2002-1119

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary f ...

CVSS2: 4.6
0%
Низкий
почти 23 года назад
redhat логотип
CVE-2002-1119

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

0%
Низкий
около 23 лет назад

Уязвимостей на страницу


Поделиться