Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 113

Количество 1 113

oracle-oval логотип

ELSA-2021-4399

почти 5 лет назад

ELSA-2021-4399: python3 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2022-45061

почти 4 года назад

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-45061

почти 4 года назад

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45061

почти 4 года назад

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45061

почти 4 года назад

An issue was discovered in Python before 3.11.1. An unnecessary quadra ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-3426

больше 5 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
EPSS: Низкий
redhat логотип

CVE-2021-3426

больше 5 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2021-3426

больше 5 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2021-3426

больше 5 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who d ...

CVSS3: 5.7
EPSS: Низкий
fstec логотип

BDU:2026-05133

8 месяцев назад

Уязвимость компонента urllib.request.DataHandler интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.7
EPSS: Низкий
fstec логотип

BDU:2026-05132

почти 2 года назад

Уязвимость модуля base64 интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2023-06655

почти 4 года назад

Уязвимость модуля plistlib интерпретатора языка программирования Python, позволяющая нарушителю проводить XXE-атаки

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-06654

почти 4 года назад

Уязвимость функции hmac.compare_digest библиотеки Lib/hmac.py интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2023-03855

около 4 лет назад

Уязвимость интерпретатора языка программирования Python, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2021-03740

около 6 лет назад

Уязвимость интерпретатора языка программирования Python, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2021-03738

почти 6 лет назад

Уязвимость метода HTTP запроса языка программирования Python, связанная с недостатком механизма кодирование или экранирование выходных данных, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2021-03708

больше 5 лет назад

Уязвимость модуля pandoc языка программирования Python, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.7
EPSS: Низкий
fstec логотип

BDU:2019-04238

около 8 лет назад

Уязвимость метода difflib.IS_LINE_JUNK интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-01741

больше 7 лет назад

Уязвимость модуля urllib интерпретатора языка программирования Python, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS2: 6.4
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2017:0839-1

больше 9 лет назад

Security update for java-1_8_0-ibm

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2021-4399

ELSA-2021-4399: python3 security update (MODERATE)

2%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
debian логотип
CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary quadra ...

CVSS3: 7.5
3%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
2%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who d ...

CVSS3: 5.7
2%
Низкий
больше 5 лет назад
fstec логотип
BDU:2026-05133

Уязвимость компонента urllib.request.DataHandler интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 7.7
1%
Низкий
8 месяцев назад
fstec логотип
BDU:2026-05132

Уязвимость модуля base64 интерпретатора языка программирования Python, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.3
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-06655

Уязвимость модуля plistlib интерпретатора языка программирования Python, позволяющая нарушителю проводить XXE-атаки

CVSS3: 9.8
5%
Низкий
почти 4 года назад
fstec логотип
BDU:2023-06654

Уязвимость функции hmac.compare_digest библиотеки Lib/hmac.py интерпретатора языка программирования Python, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
1%
Низкий
почти 4 года назад
fstec логотип
BDU:2023-03855

Уязвимость интерпретатора языка программирования Python, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
3%
Низкий
около 4 лет назад
fstec логотип
BDU:2021-03740

Уязвимость интерпретатора языка программирования Python, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
7%
Низкий
около 6 лет назад
fstec логотип
BDU:2021-03738

Уязвимость метода HTTP запроса языка программирования Python, связанная с недостатком механизма кодирование или экранирование выходных данных, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 7.2
6%
Низкий
почти 6 лет назад
fstec логотип
BDU:2021-03708

Уязвимость модуля pandoc языка программирования Python, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.7
2%
Низкий
больше 5 лет назад
fstec логотип
BDU:2019-04238

Уязвимость метода difflib.IS_LINE_JUNK интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
5%
Низкий
около 8 лет назад
fstec логотип
BDU:2019-01741

Уязвимость модуля urllib интерпретатора языка программирования Python, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS2: 6.4
12%
Средний
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2017:0839-1

Security update for java-1_8_0-ibm

96%
Критический
больше 9 лет назад

Уязвимостей на страницу