Логотип exploitDog
bind:"CVE-2025-12084" OR bind:"CVE-2025-8291"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-12084" OR bind:"CVE-2025-8291"

Количество 40

Количество 40

rocky логотип

RLSA-2026:0123

8 дней назад

Moderate: python3.12 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0123

10 дней назад

ELSA-2026-0123: python3.12 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2025-12084

около 1 месяца назад

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-12084

около 1 месяца назад

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-12084

около 1 месяца назад

Quadratic complexity in node ID cache clearing

EPSS: Низкий
debian логотип

CVE-2025-12084

около 1 месяца назад

When building nested elements using xml.dom.minidom methods such as ap ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2025-8291

3 месяца назад

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hfqx-732w-xrrw

около 1 месяца назад

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4313-1

около 2 месяцев назад

Security update for python

EPSS: Низкий
redos логотип

ROS-20251223-7310

24 дня назад

Уязвимость python3.13

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20251223-7309

24 дня назад

Уязвимость python3.11

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20251223-7308

24 дня назад

Уязвимость python3.10

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20251223-7307

24 дня назад

Уязвимость python3

CVSS3: 4.3
EPSS: Низкий
rocky логотип

RLSA-2025:23940

22 дня назад

Moderate: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23323

27 дней назад

Moderate: python3.12 security update

EPSS: Низкий
github логотип

GHSA-49g5-f6qw-8mm7

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23940

25 дней назад

ELSA-2025-23940: python3.12 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:0123

Moderate: python3.12 security update

8 дней назад
oracle-oval логотип
ELSA-2026-0123

ELSA-2026-0123: python3.12 security update (MODERATE)

10 дней назад
ubuntu логотип
CVE-2025-12084

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-12084

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-12084

Quadratic complexity in node ID cache clearing

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-12084

When building nested elements using xml.dom.minidom methods such as ap ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-8291

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-hfqx-732w-xrrw

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4313-1

Security update for python

0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20251223-7310

Уязвимость python3.13

CVSS3: 4.3
0%
Низкий
24 дня назад
redos логотип
ROS-20251223-7309

Уязвимость python3.11

CVSS3: 4.3
0%
Низкий
24 дня назад
redos логотип
ROS-20251223-7308

Уязвимость python3.10

CVSS3: 4.3
0%
Низкий
24 дня назад
redos логотип
ROS-20251223-7307

Уязвимость python3

CVSS3: 4.3
0%
Низкий
24 дня назад
rocky логотип
RLSA-2025:23940

Moderate: python3.12 security update

0%
Низкий
22 дня назад
rocky логотип
RLSA-2025:23323

Moderate: python3.12 security update

0%
Низкий
27 дней назад
github логотип
GHSA-49g5-f6qw-8mm7

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2025-23940

ELSA-2025-23940: python3.12 security update (MODERATE)

25 дней назад

Уязвимостей на страницу