Логотип exploitDog
bind:"BDU:2021-03488" OR bind:"CVE-2020-14343"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2021-03488" OR bind:"CVE-2020-14343"

Количество 14

Количество 14

fstec логотип

BDU:2021-03488

больше 4 лет назад

Уязвимость синтаксического анализатора PyYAML, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2020-14343

почти 5 лет назад

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2020-14343

больше 5 лет назад

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2020-14343

почти 5 лет назад

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
EPSS: Средний
msrc логотип

CVE-2020-14343

около 2 лет назад

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2020-14343

почти 5 лет назад

A vulnerability was discovered in the PyYAML library in versions befor ...

CVSS3: 9.8
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2022:3231-1

больше 3 лет назад

Security update for python-PyYAML

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:2818-1

больше 4 лет назад

Security update for python-PyYAML

EPSS: Средний
rocky логотип

RLSA-2021:2583

больше 4 лет назад

Moderate: python38:3.8 and python38-devel:3.8 security update

EPSS: Средний
github логотип

GHSA-8q59-q68h-6hv4

больше 4 лет назад

Improper Input Validation in PyYAML

CVSS3: 9.8
EPSS: Средний
oracle-oval логотип

ELSA-2021-2583

больше 4 лет назад

ELSA-2021-2583: python38:3.8 and python38-devel:3.8 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2841-1

больше 3 лет назад

Security update for python-PyYAML

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2021:0985-1

больше 4 лет назад

Recommended update for the Azure SDK and CLI

EPSS: Низкий
fstec логотип

BDU:2023-05108

больше 5 лет назад

Уязвимость компонента ext/fts3/fts3.c системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-03488

Уязвимость синтаксического анализатора PyYAML, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
14%
Средний
больше 4 лет назад
ubuntu логотип
CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
14%
Средний
почти 5 лет назад
redhat логотип
CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
14%
Средний
больше 5 лет назад
nvd логотип
CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

CVSS3: 9.8
14%
Средний
почти 5 лет назад
msrc логотип
CVSS3: 9.8
14%
Средний
около 2 лет назад
debian логотип
CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions befor ...

CVSS3: 9.8
14%
Средний
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:3231-1

Security update for python-PyYAML

14%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:2818-1

Security update for python-PyYAML

14%
Средний
больше 4 лет назад
rocky логотип
RLSA-2021:2583

Moderate: python38:3.8 and python38-devel:3.8 security update

14%
Средний
больше 4 лет назад
github логотип
GHSA-8q59-q68h-6hv4

Improper Input Validation in PyYAML

CVSS3: 9.8
14%
Средний
больше 4 лет назад
oracle-oval логотип
ELSA-2021-2583

ELSA-2021-2583: python38:3.8 and python38-devel:3.8 security update (MODERATE)

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:2841-1

Security update for python-PyYAML

больше 3 лет назад
suse-cvrf логотип
SUSE-RU-2021:0985-1

Recommended update for the Azure SDK and CLI

больше 4 лет назад
fstec логотип
BDU:2023-05108

Уязвимость компонента ext/fts3/fts3.c системы управления базами данных SQLite, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу