Логотип exploitDog
bind:"BDU:2025-03332" OR bind:"CVE-2024-9287"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-03332" OR bind:"CVE-2024-9287"

Количество 28

Количество 28

fstec логотип

BDU:2025-03332

8 месяцев назад

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-9287

8 месяцев назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-9287

8 месяцев назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-9287

8 месяцев назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2024-9287

3 месяца назад

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-9287

8 месяцев назад

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0048-1

5 месяцев назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3959-1

7 месяцев назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3958-1

7 месяцев назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3957-1

7 месяцев назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3945-1

7 месяцев назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3944-1

7 месяцев назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3929-1

7 месяцев назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3924-1

8 месяцев назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3879-1

8 месяцев назад

Security update for python3

EPSS: Низкий
redos логотип

ROS-20250212-03

4 месяца назад

Уязвимость python3

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2024:10979

6 месяцев назад

Moderate: python3.11 security update

EPSS: Низкий
github логотип

GHSA-grqq-hcc7-crmr

8 месяцев назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-11111

6 месяцев назад

ELSA-2024-11111: python3.11 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10979

6 месяцев назад

ELSA-2024-10979: python3.11 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03332

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
msrc логотип
CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0048-1

Security update for python312

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3959-1

Security update for python312

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3958-1

Security update for python311

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3957-1

Security update for python311

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3945-1

Security update for python39

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3944-1

Security update for python3

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3929-1

Security update for python36

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3924-1

Security update for python310

0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3879-1

Security update for python3

0%
Низкий
8 месяцев назад
redos логотип
ROS-20250212-03

Уязвимость python3

CVSS3: 7.8
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2024:10979

Moderate: python3.11 security update

0%
Низкий
6 месяцев назад
github логотип
GHSA-grqq-hcc7-crmr

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2024-11111

ELSA-2024-11111: python3.11 security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2024-10979

ELSA-2024-10979: python3.11 security update (MODERATE)

6 месяцев назад

Уязвимостей на страницу