Логотип exploitDog
bind:"CVE-2024-4032" OR bind:"CVE-2024-6345" OR bind:"CVE-2024-6923" OR bind:"CVE-2024-8088"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-4032" OR bind:"CVE-2024-6345" OR bind:"CVE-2024-6923" OR bind:"CVE-2024-8088"

Количество 98

Количество 98

github логотип

GHSA-mh6q-v4mp-2cc7

больше 1 года назад

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-4779

больше 1 года назад

ELSA-2024-4779: python3 security update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4766

больше 1 года назад

ELSA-2024-4766: python3 security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2024-05196

почти 2 года назад

Уязвимость классов ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address и ipaddress.IPv6Network модуля ipaddress интерпретатора языка программирования Python (CPython), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2280-1

больше 1 года назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2274-1

больше 1 года назад

Security update for python39

EPSS: Низкий
redos логотип

ROS-20240917-08

около 1 года назад

Уязвимость python3

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2572-1

больше 1 года назад

Security update for python312

EPSS: Низкий
ubuntu логотип

CVE-2024-6345

больше 1 года назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2024-6345

больше 1 года назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-6345

больше 1 года назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2024-6345

около 1 года назад

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-6345

больше 1 года назад

A vulnerability in the package_index module of pypa/setuptools version ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3303-1

около 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2479-1

больше 1 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3055-1

больше 1 года назад

Security update for python-setuptools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3054-1

больше 1 года назад

Security update for python3-setuptools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2950-1

больше 1 года назад

Security update for python36-setuptools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2907-1

больше 1 года назад

Security update for python310-setuptools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2906-1

больше 1 года назад

Security update for python39-setuptools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mh6q-v4mp-2cc7

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-4779

ELSA-2024-4779: python3 security update (LOW)

больше 1 года назад
oracle-oval логотип
ELSA-2024-4766

ELSA-2024-4766: python3 security update (LOW)

больше 1 года назад
fstec логотип
BDU:2024-05196

Уязвимость классов ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address и ipaddress.IPv6Network модуля ipaddress интерпретатора языка программирования Python (CPython), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.7
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:2280-1

Security update for python39

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2274-1

Security update for python39

больше 1 года назад
redos логотип
ROS-20240917-08

Уязвимость python3

CVSS3: 3.7
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2572-1

Security update for python312

больше 1 года назад
ubuntu логотип
CVE-2024-6345

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-6345

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6345

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 8.8
5%
Низкий
около 1 года назад
debian логотип
CVE-2024-6345

A vulnerability in the package_index module of pypa/setuptools version ...

CVSS3: 8.8
5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3303-1

Security update for python312

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2479-1

Security update for python3

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3055-1

Security update for python-setuptools

5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3054-1

Security update for python3-setuptools

5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2950-1

Security update for python36-setuptools

5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2907-1

Security update for python310-setuptools

5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2906-1

Security update for python39-setuptools

5%
Низкий
больше 1 года назад

Уязвимостей на страницу