Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 998

Количество 998

debian логотип

CVE-2019-10160

около 7 лет назад

A security regression of CVE-2019-9636 was discovered in python since ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2015-20107

почти 11 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2009-3720

больше 17 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2009-3720

больше 16 лет назад

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ...

CVSS2: 5
EPSS: Средний
fstec логотип

BDU:2025-04572

больше 1 года назад

Уязвимость функций urllib.parse.urlsplit() и urlparse() интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2022-05975

почти 19 лет назад

Уязвимость функций extract и extractall модуля tarfile интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Средний
fstec логотип

BDU:2022-05830

около 5 лет назад

Уязвимость компонента urllib интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2639-1

около 3 лет назад

Security update for python

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0868-1

больше 3 лет назад

Security update for python3

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0736-1

больше 3 лет назад

Security update for python3

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0662-1

больше 3 лет назад

Security update for python36

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:14198-1

больше 5 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2020:1342-1

около 6 лет назад

Recommended update for python3

EPSS: Низкий
rocky логотип

RLSA-2023:3811

почти 3 года назад

Important: python39:3.9 and python39-devel:3.9 security update

EPSS: Средний
rocky логотип

RLSA-2023:3781

почти 3 года назад

Important: python38:3.8 and python38-devel:3.8 security update

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2019-10160

A security regression of CVE-2019-9636 was discovered in python since ...

CVSS3: 9.8
5%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
redhat логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
debian логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module does not add ...

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
28%
Средний
больше 16 лет назад
redhat логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
28%
Средний
больше 17 лет назад
nvd логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS2: 5
28%
Средний
больше 16 лет назад
debian логотип
CVE-2009-3720

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ...

CVSS2: 5
28%
Средний
больше 16 лет назад
fstec логотип
BDU:2025-04572

Уязвимость функций urllib.parse.urlsplit() и urlparse() интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.8
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2022-05975

Уязвимость функций extract и extractall модуля tarfile интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
27%
Средний
почти 19 лет назад
fstec логотип
BDU:2022-05830

Уязвимость компонента urllib интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
12%
Средний
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2023:2639-1

Security update for python

20%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0868-1

Security update for python3

20%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0736-1

Security update for python3

20%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0662-1

Security update for python36

20%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:14198-1

Security update for python

5%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-RU-2020:1342-1

Recommended update for python3

5%
Низкий
около 6 лет назад
rocky логотип
RLSA-2023:3811

Important: python39:3.9 and python39-devel:3.9 security update

20%
Средний
почти 3 года назад
rocky логотип
RLSA-2023:3781

Important: python38:3.8 and python38-devel:3.8 security update

20%
Средний
почти 3 года назад

Уязвимостей на страницу