Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

fstec логотип

BDU:2026-01708

6 месяцев назад

Уязвимость функции commonprefix() модуля pip языка программирования Python, позволяющая нарушителю получить доступ на добавление и изменение произвольных файлов

CVSS3: 3.5
EPSS: Низкий
redos логотип

ROS-20260417-73-0013

4 месяца назад

Уязвимость python-pip

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2026-1703

6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

EPSS: Низкий
redhat логотип

CVE-2026-1703

6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

CVSS3: 3.9
EPSS: Низкий
nvd логотип

CVE-2026-1703

6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

EPSS: Низкий
msrc логотип

CVE-2026-1703

6 месяцев назад

Limited path traversal when installing wheel archives

EPSS: Низкий
debian логотип

CVE-2026-1703

6 месяцев назад

When pip is installing and extracting a maliciously crafted wheel arch ...

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20202-1

6 месяцев назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0805-1

5 месяцев назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0420-1

6 месяцев назад

Security update for python-pip

EPSS: Низкий
github логотип

GHSA-6vgw-5pg2-w6jp

6 месяцев назад

pip Path Traversal vulnerability

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20880-1

2 месяца назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2387-1

около 2 месяцев назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2664-1

около 1 месяца назад

Security update for python, python-base, python-doc

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-01708

Уязвимость функции commonprefix() модуля pip языка программирования Python, позволяющая нарушителю получить доступ на добавление и изменение произвольных файлов

CVSS3: 3.5
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260417-73-0013

Уязвимость python-pip

CVSS3: 3.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

CVSS3: 3.9
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

0%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-1703

Limited path traversal when installing wheel archives

0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-1703

When pip is installing and extracting a maliciously crafted wheel arch ...

0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20202-1

Security update for python-pip

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0805-1

Security update for python-pip

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0420-1

Security update for python-pip

0%
Низкий
6 месяцев назад
github логотип
GHSA-6vgw-5pg2-w6jp

pip Path Traversal vulnerability

0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20880-1

Security update for python-pip

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2387-1

Security update for python

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2664-1

Security update for python, python-base, python-doc

около 1 месяца назад

Уязвимостей на страницу