Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 91

Количество 91

suse-cvrf логотип

SUSE-SU-2025:02359-1

10 месяцев назад

Security update for python312

EPSS: Низкий
redos логотип

ROS-20260129-73-0015

6 месяцев назад

Уязвимость python3

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02802-1

12 месяцев назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02767-1

12 месяцев назад

Security update for python313

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02717-1

12 месяцев назад

Security update for python311

EPSS: Низкий
ubuntu логотип

CVE-2025-8291

10 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2025-8291

10 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-8291

10 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2025-8291

10 месяцев назад

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-8291

10 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-6075

9 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2025-6075

9 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-6075

9 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2025-6075

9 месяцев назад

Quadratic complexity in os.path.expandvars() with user-controlled template

EPSS: Низкий
debian логотип

CVE-2025-6075

9 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a perf ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02297-1

около 1 года назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4313-1

8 месяцев назад

Security update for python

EPSS: Низкий
rocky логотип

RLSA-2025:23940

7 месяцев назад

Moderate: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23323

7 месяцев назад

Moderate: python3.12 security update

EPSS: Низкий
github логотип

GHSA-49g5-f6qw-8mm7

10 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2025:02359-1

Security update for python312

10 месяцев назад
redos логотип
ROS-20260129-73-0015

Уязвимость python3

CVSS3: 4.3
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02802-1

Security update for python3

12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02767-1

Security update for python313

12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02717-1

Security update for python311

12 месяцев назад
ubuntu логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
msrc логотип
CVE-2025-8291

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
redhat логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 4
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
msrc логотип
CVE-2025-6075

Quadratic complexity in os.path.expandvars() with user-controlled template

0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a perf ...

CVSS3: 5.5
0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02297-1

Security update for python36

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:4313-1

Security update for python

0%
Низкий
8 месяцев назад
rocky логотип
RLSA-2025:23940

Moderate: python3.12 security update

0%
Низкий
7 месяцев назад
rocky логотип
RLSA-2025:23323

Moderate: python3.12 security update

0%
Низкий
7 месяцев назад
github логотип
GHSA-49g5-f6qw-8mm7

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу