Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 34

Количество 34

fstec логотип

BDU:2025-03332

почти 2 года назад

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20250212-03

больше 1 года назад

Уязвимость python3

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2024-9287

почти 2 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-9287

почти 2 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-9287

почти 2 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2024-9287

больше 1 года назад

Virtual environment (venv) activation scripts don't quote paths

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-9287

почти 2 года назад

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0048-1

больше 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3959-1

больше 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3958-1

больше 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3957-1

больше 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3945-1

больше 1 года назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3944-1

больше 1 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3929-1

больше 1 года назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3924-1

больше 1 года назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3879-1

больше 1 года назад

Security update for python3

EPSS: Низкий
rocky логотип

RLSA-2024:11111

больше 1 года назад

Moderate: python3.11 security update

EPSS: Низкий
rocky логотип

RLSA-2024:10979

больше 1 года назад

Moderate: python3.11 security update

EPSS: Низкий
github логотип

GHSA-grqq-hcc7-crmr

почти 2 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-11111

больше 1 года назад

ELSA-2024-11111: python3.11 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03332

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
1%
Низкий
почти 2 года назад
redos логотип
ROS-20250212-03

Уязвимость python3

CVSS3: 7.8
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-9287

Virtual environment (venv) activation scripts don't quote paths

CVSS3: 7.8
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2025:0048-1

Security update for python312

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3959-1

Security update for python312

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3958-1

Security update for python311

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3957-1

Security update for python311

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3945-1

Security update for python39

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3944-1

Security update for python3

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3929-1

Security update for python36

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3924-1

Security update for python310

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3879-1

Security update for python3

1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:11111

Moderate: python3.11 security update

1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:10979

Moderate: python3.11 security update

1%
Низкий
больше 1 года назад
github логотип
GHSA-grqq-hcc7-crmr

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
oracle-oval логотип
ELSA-2024-11111

ELSA-2024-11111: python3.11 security update (MODERATE)

больше 1 года назад

Уязвимостей на страницу