Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77

Количество 77

rocky логотип

RLSA-2025:14900

около 1 года назад

Moderate: python39:3.9 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-14900

около 1 года назад

ELSA-2025-14900: python39:3.9 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2025-8194

около 1 года назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-8194

около 1 года назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-8194

около 1 года назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-8194

7 месяцев назад

Tarfile infinite loop during parsing with negative member offset

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-8194

около 1 года назад

There is a defect in the CPython \u201ctarfile\u201d module affecting ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-47273

больше 1 года назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-47273

больше 1 года назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-47273

больше 1 года назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2025-47273

больше 1 года назад

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-47273

больше 1 года назад

setuptools is a package that allows users to download, build, install, ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03032-1

около 1 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02984-1

около 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02983-1

около 1 года назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02982-1

около 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02948-1

около 1 года назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02701-1

около 1 года назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02700-1

около 1 года назад

Security update for python39

EPSS: Низкий
rocky логотип

RLSA-2025:15019

12 месяцев назад

Moderate: python3.9 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:14900

Moderate: python39:3.9 security update

около 1 года назад
oracle-oval логотип
ELSA-2025-14900

ELSA-2025-14900: python39:3.9 security update (MODERATE)

около 1 года назад
ubuntu логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-8194

Tarfile infinite loop during parsing with negative member offset

CVSS3: 7.5
1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-8194

There is a defect in the CPython \u201ctarfile\u201d module affecting ...

CVSS3: 7.5
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-47273

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-47273

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 7.1
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-47273

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-47273

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

CVSS3: 8.8
2%
Низкий
больше 1 года назад
debian логотип
CVE-2025-47273

setuptools is a package that allows users to download, build, install, ...

CVSS3: 8.8
2%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:03032-1

Security update for python

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02984-1

Security update for python311

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02983-1

Security update for python36

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02982-1

Security update for python312

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02948-1

Security update for python310

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02701-1

Security update for python

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02700-1

Security update for python39

1%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:15019

Moderate: python3.9 security update

1%
Низкий
12 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.