Логотип exploitDog
bind:"CVE-2024-5642" OR bind:"CVE-2025-6069" OR bind:"CVE-2025-6075" OR bind:"CVE-2025-8291"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-5642" OR bind:"CVE-2025-6069" OR bind:"CVE-2025-6075" OR bind:"CVE-2025-8291"

Количество 55

Количество 55

msrc логотип

CVE-2025-6075

около 2 месяцев назад

Quadratic complexity in os.path.expandvars() with user-controlled template

EPSS: Низкий
debian логотип

CVE-2025-6075

около 2 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a perf ...

EPSS: Низкий
ubuntu логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2025-8291

2 месяца назад

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-8291

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02802-1

4 месяца назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02767-1

4 месяца назад

Security update for python313

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02717-1

5 месяцев назад

Security update for python311

EPSS: Низкий
github логотип

GHSA-vc2m-m665-8xm2

около 2 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4313-1

20 дней назад

Security update for python

EPSS: Низкий
github логотип

GHSA-49g5-f6qw-8mm7

3 месяца назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23323

4 дня назад

ELSA-2025-23323: python3.12 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02297-1

5 месяцев назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02778-1

4 месяца назад

Security update for python3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2025-6075

Quadratic complexity in os.path.expandvars() with user-controlled template

0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a perf ...

0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-8291

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02802-1

Security update for python3

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02767-1

Security update for python313

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02717-1

Security update for python311

5 месяцев назад
github логотип
GHSA-vc2m-m665-8xm2

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4313-1

Security update for python

0%
Низкий
20 дней назад
github логотип
GHSA-49g5-f6qw-8mm7

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2025-23323

ELSA-2025-23323: python3.12 security update (MODERATE)

4 дня назад
suse-cvrf логотип
SUSE-SU-2025:02297-1

Security update for python36

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02778-1

Security update for python3

4 месяца назад

Уязвимостей на страницу