Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 998

Количество 998

debian логотип

CVE-2014-4616

почти 9 лет назад

Array index error in the scanstring function in the _json module in Py ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2013-0340

больше 12 лет назад

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2013-0340

больше 13 лет назад

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-0340

больше 12 лет назад

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2013-0340

больше 12 лет назад

expat before version 2.4.0 does not properly handle entities expansion ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2009-2940

почти 17 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-2940

почти 17 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2009-2940

почти 17 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-2940

почти 17 лет назад

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-09235

около 4 лет назад

Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2024-08836

около 3 лет назад

Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-08617

около 2 лет назад

Уязвимость функции mkdtemp интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2021-03533

больше 8 лет назад

Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2018-01554

почти 8 лет назад

Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2020:1988-1

больше 5 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1859-1

больше 5 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0595-1

больше 2 лет назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0581-1

больше 2 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0438-1

больше 2 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0437-1

больше 2 лет назад

Security update for python

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-4616

Array index error in the scanstring function in the _json module in Py ...

CVSS3: 5.9
8%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2013-0340

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
20%
Средний
больше 12 лет назад
redhat логотип
CVE-2013-0340

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 4.3
20%
Средний
больше 13 лет назад
nvd логотип
CVE-2013-0340

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CVSS2: 6.8
20%
Средний
больше 12 лет назад
debian логотип
CVE-2013-0340

expat before version 2.4.0 does not properly handle entities expansion ...

CVSS2: 6.8
20%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
redhat логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS3: 5.4
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-2940

The pygresql module 3.8.1 and 4.0 for Python does not properly support ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
fstec логотип
BDU:2024-09235

Уязвимость библиотеки python3.dll интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

CVSS3: 7.8
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2024-08836

Уязвимость компонента _asyncio._swap_current_task интерпретатора языка программирования Python, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.3
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-08617

Уязвимость функции mkdtemp интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2021-03533

Уязвимость библиотеки library/glob.html пакета программ Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.5
5%
Низкий
больше 8 лет назад
fstec логотип
BDU:2018-01554

Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.5
11%
Средний
почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1988-1

Security update for python

6%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1859-1

Security update for python

6%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2024:0595-1

Security update for python310

3%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0581-1

Security update for python3

3%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0438-1

Security update for python3

3%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0437-1

Security update for python

3%
Низкий
больше 2 лет назад

Уязвимостей на страницу