Количество 67
Количество 67
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVE-2026-4786
Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...
GHSA-pg25-7cx5-cvcm
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.
BDU:2026-05838
Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании
GHSA-cccx-m78h-m3xw
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
ELSA-2026-35838
ELSA-2026-35838: python3 security update (IMPORTANT)
ELSA-2026-19589
ELSA-2026-19589: python security update (IMPORTANT)
BDU:2026-09777
Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды
ROS-20260623-73-0046
Уязвимость python3.13
ROS-20260623-73-0045
Уязвимость python3.12
ROS-20260623-73-0044
Уязвимость python3.11
ROS-20260623-73-0043
Уязвимость python3.10
ROS-20260623-73-0042
Уязвимость python3.9
ROS-20260623-73-0041
Уязвимость python3
ROS-20260623-73-0016
Уязвимость python3.13
ROS-20260623-73-0015
Уязвимость python3.12
ROS-20260623-73-0014
Уязвимость python3.11
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | 0% Низкий | 3 месяца назад | ||
CVE-2026-4786 Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ... | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-pg25-7cx5-cvcm Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable. | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
BDU:2026-05838 Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.7 | 1% Низкий | 4 месяца назад | |
GHSA-cccx-m78h-m3xw Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
ELSA-2026-35838 ELSA-2026-35838: python3 security update (IMPORTANT) | 10 дней назад | |||
ELSA-2026-19589 ELSA-2026-19589: python security update (IMPORTANT) | около 1 месяца назад | |||
BDU:2026-09777 Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
ROS-20260623-73-0046 Уязвимость python3.13 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0045 Уязвимость python3.12 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0044 Уязвимость python3.11 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0043 Уязвимость python3.10 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0042 Уязвимость python3.9 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0041 Уязвимость python3 | CVSS3: 8.7 | 1% Низкий | около 1 месяца назад | |
ROS-20260623-73-0016 Уязвимость python3.13 | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
ROS-20260623-73-0015 Уязвимость python3.12 | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
ROS-20260623-73-0014 Уязвимость python3.11 | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу