Количество 924
Количество 924
CVE-2014-4616
Array index error in the scanstring function in the _json module in Py ...
CVE-2013-0340
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
CVE-2013-0340
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
CVE-2013-0340
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
CVE-2013-0340
expat before version 2.4.0 does not properly handle entities expansion ...
CVE-2009-2940
The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
CVE-2009-2940
The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
CVE-2009-2940
The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
CVE-2009-2940
The pygresql module 3.8.1 and 4.0 for Python does not properly support ...
BDU:2025-13251
Уязвимость модуля tarfile языка программирования Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
BDU:2024-09235
Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации
BDU:2024-08836
Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации
BDU:2024-08617
Уязвимость функции mkdtemp интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии
BDU:2021-03533
Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
BDU:2018-01554
Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2020:1988-1
Security update for python
openSUSE-SU-2020:1859-1
Security update for python
SUSE-SU-2024:0595-1
Security update for python310
SUSE-SU-2024:0581-1
Security update for python3
SUSE-SU-2024:0438-1
Security update for python3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2014-4616 Array index error in the scanstring function in the _json module in Py ... | CVSS3: 5.9 | 1% Низкий | больше 8 лет назад | |
CVE-2013-0340 expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. | CVSS2: 6.8 | 0% Низкий | около 12 лет назад | |
CVE-2013-0340 expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. | CVSS2: 4.3 | 0% Низкий | около 13 лет назад | |
CVE-2013-0340 expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. | CVSS2: 6.8 | 0% Низкий | около 12 лет назад | |
CVE-2013-0340 expat before version 2.4.0 does not properly handle entities expansion ... | CVSS2: 6.8 | 0% Низкий | около 12 лет назад | |
CVE-2009-2940 The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. | CVSS2: 7.5 | 1% Низкий | больше 16 лет назад | |
CVE-2009-2940 The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. | CVSS3: 5.4 | 1% Низкий | больше 16 лет назад | |
CVE-2009-2940 The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. | CVSS2: 7.5 | 1% Низкий | больше 16 лет назад | |
CVE-2009-2940 The pygresql module 3.8.1 and 4.0 for Python does not properly support ... | CVSS2: 7.5 | 1% Низкий | больше 16 лет назад | |
BDU:2025-13251 Уязвимость модуля tarfile языка программирования Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 5.7 | 0% Низкий | 6 месяцев назад | |
BDU:2024-09235 Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
BDU:2024-08836 Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
BDU:2024-08617 Уязвимость функции mkdtemp интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии | CVSS3: 7.1 | 0% Низкий | почти 2 года назад | |
BDU:2021-03533 Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 7.5 | 2% Низкий | почти 8 лет назад | |
BDU:2018-01554 Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 3.5 | 2% Низкий | больше 7 лет назад | |
openSUSE-SU-2020:1988-1 Security update for python | 1% Низкий | больше 5 лет назад | ||
openSUSE-SU-2020:1859-1 Security update for python | 1% Низкий | больше 5 лет назад | ||
SUSE-SU-2024:0595-1 Security update for python310 | 0% Низкий | около 2 лет назад | ||
SUSE-SU-2024:0581-1 Security update for python3 | 0% Низкий | около 2 лет назад | ||
SUSE-SU-2024:0438-1 Security update for python3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу