Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"
Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.93.103.113.123.1320202021202220232024202520262027202820292030

Недавние уязвимости Python

Количество 870

debian логотип

CVE-2022-48565

почти 2 года назад

An XML External Entity (XXE) issue was discovered in Python through 3. ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-48564

почти 2 года назад

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-48564

почти 2 года назад

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a po ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-48560

почти 2 года назад

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-48560

почти 2 года назад

A use-after-free exists in Python through 3.9 via heappushpop in heapq ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-48565

почти 2 года назад

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-48566

почти 2 года назад

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-48560

почти 2 года назад

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-48564

почти 2 года назад

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-48564

почти 2 года назад

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-48565

An XML External Entity (XXE) issue was discovered in Python through 3. ...

CVSS3: 9.8
4%
Низкий
почти 2 года назад
nvd логотип
CVE-2022-48564

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2022-48564

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a po ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2022-48560

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2022-48560

A use-after-free exists in Python through 3.9 via heappushpop in heapq ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2022-48565

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2022-48566

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2022-48560

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2022-48564

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2022-48564

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться