Логотип exploitDog
bind:"CVE-2013-1752" OR bind:"CVE-2014-1912" OR bind:"CVE-2014-7185" OR bind:"CVE-2014-4650"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2013-1752" OR bind:"CVE-2014-1912" OR bind:"CVE-2014-7185" OR bind:"CVE-2014-4650"

Количество 27

Количество 27

oracle-oval логотип

ELSA-2015-1330

почти 10 лет назад

ELSA-2015-1330: python security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1064

больше 9 лет назад

ELSA-2015-1064: python27 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1344-1

почти 10 лет назад

Security update for python

EPSS: Низкий
oracle-oval логотип

ELSA-2015-2101

больше 9 лет назад

ELSA-2015-2101: python security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0234-1

больше 5 лет назад

Security update for python

EPSS: Низкий
ubuntu логотип

CVE-2013-1752

около 6 лет назад

** REJECT ** Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions.

EPSS: Низкий
redhat логотип

CVE-2013-1752

больше 12 лет назад

It was discovered that multiple Python standard library modules implementing network protocols (such as httplib or smtplib) failed to restrict sizes of server responses. A malicious server could cause a client using one of the affected modules to consume an excessive amount of memory.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1752

около 6 лет назад

Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions

EPSS: Низкий
ubuntu логотип

CVE-2014-1912

больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2014-1912

больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2014-1912

больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-1912

больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socket ...

CVSS2: 7.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2020:0086-1

больше 5 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0114-1

больше 5 лет назад

Security update for python3

EPSS: Низкий
github логотип

GHSA-jhx7-j4rm-xpm8

около 3 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

EPSS: Средний
ubuntu логотип

CVE-2014-7185

больше 10 лет назад

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2014-7185

почти 11 лет назад

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7185

больше 10 лет назад

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2014-7185

больше 10 лет назад

Integer overflow in bufferobject.c in Python before 2.7.8 allows conte ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2014-4650

больше 5 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2015-1330

ELSA-2015-1330: python security, bug fix, and enhancement update (MODERATE)

почти 10 лет назад
oracle-oval логотип
ELSA-2015-1064

ELSA-2015-1064: python27 security, bug fix, and enhancement update (MODERATE)

больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2015:1344-1

Security update for python

почти 10 лет назад
oracle-oval логотип
ELSA-2015-2101

ELSA-2015-2101: python security, bug fix, and enhancement update (MODERATE)

больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2020:0234-1

Security update for python

больше 5 лет назад
ubuntu логотип
CVE-2013-1752

** REJECT ** Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions.

около 6 лет назад
redhat логотип
CVE-2013-1752

It was discovered that multiple Python standard library modules implementing network protocols (such as httplib or smtplib) failed to restrict sizes of server responses. A malicious server could cause a client using one of the affected modules to consume an excessive amount of memory.

CVSS2: 4.3
больше 12 лет назад
nvd логотип
CVE-2013-1752

Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions

около 6 лет назад
ubuntu логотип
CVE-2014-1912

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 7.5
26%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-1912

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 5.1
26%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-1912

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

CVSS2: 7.5
26%
Средний
больше 11 лет назад
debian логотип
CVE-2014-1912

Buffer overflow in the socket.recvfrom_into function in Modules/socket ...

CVSS2: 7.5
26%
Средний
больше 11 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0086-1

Security update for python3

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0114-1

Security update for python3

больше 5 лет назад
github логотип
GHSA-jhx7-j4rm-xpm8

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

26%
Средний
около 3 лет назад
ubuntu логотип
CVE-2014-7185

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-7185

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 4
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-7185

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7185

Integer overflow in bufferobject.c in Python before 2.7.8 allows conte ...

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-4650

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
10%
Средний
больше 5 лет назад

Уязвимостей на страницу