Логотип exploitDog
product: "python"
Консоль
Логотип exploitDog

exploitDog

product: "python"

Количество 879

Количество 879

redhat логотип

CVE-2014-4650

около 11 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2014-4650

больше 5 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2014-4650

больше 5 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2014-4616

почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2014-4616

около 11 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-4616

почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2014-4616

почти 8 лет назад

Array index error in the scanstring function in the _json module in Py ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2013-0340

больше 11 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2013-0340

больше 12 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0340

больше 11 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-0340

больше 11 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion un ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2009-2940

почти 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-2940

почти 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2009-2940

почти 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-2940

почти 16 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-09235

около 3 лет назад

Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2024-08836

около 2 лет назад

Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2021-03533

больше 7 лет назад

Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2018-01554

почти 7 лет назад

Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1988-1

больше 4 лет назад

Security update for python

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS2: 5
14%
Средний
около 11 лет назад
nvd логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
14%
Средний
больше 5 лет назад
debian логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly h ...

CVSS3: 9.8
14%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2014-4616

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2014-4616

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS2: 4
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-4616

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2014-4616

Array index error in the scanstring function in the _json module in Py ...

CVSS3: 5.9
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion un ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
redhat логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
fstec логотип
BDU:2024-09235

Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 7.8
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-08836

Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.3
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2021-03533

Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
fstec логотип
BDU:2018-01554

Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.5
1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1988-1

Security update for python

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу