Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 126

Количество 126

oracle-oval логотип

ELSA-2026-6256

6 месяцев назад

ELSA-2026-6256: python3.12 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-07233

6 месяцев назад

Уязвимость функции webbrowser.open() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2664-1

3 месяца назад

Security update for python, python-base, python-doc

EPSS: Низкий
redos логотип

ROS-20260505-73-0009

4 месяца назад

Уязвимость python3.13

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260505-73-0008

4 месяца назад

Уязвимость python3.12

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260505-73-0007

4 месяца назад

Уязвимость python3.11

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260505-73-0006

4 месяца назад

Уязвимость python3.10

CVSS3: 7.1
EPSS: Низкий
rocky логотип

RLSA-2026:10950

5 месяцев назад

Important: python3.12 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10950

5 месяцев назад

ELSA-2026-10950: python3.12 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2026-6100

3 месяца назад

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-6100

5 месяцев назад

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-4786

5 месяцев назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-4786

5 месяцев назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-4786

5 месяцев назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2026-4786

5 месяцев назад

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

EPSS: Низкий
debian логотип

CVE-2026-4786

5 месяцев назад

Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3855-1

17 дней назад

Security update for python36

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-6256

ELSA-2026-6256: python3.12 security update (IMPORTANT)

0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-07233

Уязвимость функции webbrowser.open() интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2664-1

Security update for python, python-base, python-doc

3 месяца назад
redos логотип
ROS-20260505-73-0009

Уязвимость python3.13

CVSS3: 7.1
0%
Низкий
4 месяца назад
redos логотип
ROS-20260505-73-0008

Уязвимость python3.12

CVSS3: 7.1
0%
Низкий
4 месяца назад
redos логотип
ROS-20260505-73-0007

Уязвимость python3.11

CVSS3: 7.1
0%
Низкий
4 месяца назад
redos логотип
ROS-20260505-73-0006

Уязвимость python3.10

CVSS3: 7.1
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:10950

Important: python3.12 security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-10950

ELSA-2026-10950: python3.12 security update (IMPORTANT)

5 месяцев назад
ubuntu логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-6100

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

CVSS3: 8.1
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...

CVSS3: 8.1
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-4786

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-4786

Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...

CVSS3: 7.1
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3855-1

Security update for python36

17 дней назад

Уязвимостей на страницу