Количество 82
Количество 82
CVE-2026-6100
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-4786
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVE-2026-4786
Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...
SUSE-SU-2026:3855-1
Security update for python36
GHSA-pg25-7cx5-cvcm
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.
BDU:2026-05838
Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260623-80-0025
Уязвимость python3.13
ROS-20260623-80-0024
Уязвимость python3.12
ROS-20260623-80-0023
Уязвимость python3.11
ROS-20260623-80-0022
Уязвимость python3.10
ROS-20260623-80-0021
Уязвимость python3.9
ROS-20260623-80-0020
Уязвимость python3.8
GHSA-cccx-m78h-m3xw
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
ELSA-2026-35838
ELSA-2026-35838: python3 security update (IMPORTANT)
ELSA-2026-19589
ELSA-2026-19589: python security update (IMPORTANT)
BDU:2026-09777
Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды
ROS-20260623-80-0056
Уязвимость python3.13
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6100 Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ... | CVSS3: 8.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | 0% Низкий | 5 месяцев назад | ||
CVE-2026-4786 Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ... | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:3855-1 Security update for python36 | 17 дней назад | |||
GHSA-pg25-7cx5-cvcm Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable. | CVSS3: 8.1 | 1% Низкий | 5 месяцев назад | |
BDU:2026-05838 Уязвимость функций lzma.LZMADecompressor(), bz2.BZ2Decompressor() и gzip.GzipFile() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.7 | 1% Низкий | 5 месяцев назад | |
ROS-20260623-80-0025 Уязвимость python3.13 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0024 Уязвимость python3.12 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0023 Уязвимость python3.11 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0022 Уязвимость python3.10 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0021 Уязвимость python3.9 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20260623-80-0020 Уязвимость python3.8 | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-cccx-m78h-m3xw Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
ELSA-2026-35838 ELSA-2026-35838: python3 security update (IMPORTANT) | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-19589 ELSA-2026-19589: python security update (IMPORTANT) | 0% Низкий | 3 месяца назад | ||
BDU:2026-09777 Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад | |
ROS-20260623-80-0056 Уязвимость python3.13 | CVSS3: 8.7 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу