Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-38898 An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disp… Python Patch available Fix from $1,6002023-08-15 HIGH 7.5 CVE-2023-36632 The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded whil… Python after 3.11.4 Fix from $1,9502023-06-25 MEDIUM 5.5 CVE-2023-33595 CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. Python Patch available Fix from $1,6002023-06-07 MEDIUM 6.1 CVE-2023-32681 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an … Requests 2.31.0+ Fix from $1,6002023-05-26 HIGH 7.5 CVE-2023-24329EPSS 20% An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with bl… Python 3.7.17 / 3.8.17+ Fix from $1,9502023-02-17 MEDIUM 5.9 CVE-2022-40897 Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or cust… Setuptools 65.5.1+ Fix from $1,6002022-12-23 HIGH 7.5 CVE-2022-45198 Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). Pillow 9.2.0+ Fix from $1,9502022-11-14 HIGH 7.5 CVE-2022-45199 Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. Pillow 9.3.0+ Fix from $1,9502022-11-14 HIGH 7.5 CVE-2022-45061 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3… Python after 3.10.8 Fix from $1,9502022-11-09 HIGH 7.8 CVE-2022-42919 Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces… Python 3.9.16 / 3.10.9+ Fix from $1,9502022-11-07 HIGH 7.5 CVE-2020-10735EPSS 6% A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to … Python 3.7.14 / 3.8.14+ Fix from $1,9502022-09-09 MEDIUM 5.3 CVE-2021-4189 A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client t… Python 3.6.14 / 3.7.11+ Fix from $1,6002022-08-24 HIGH 7.4 CVE-2021-28861 Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI… Python 3.7.14 / 3.8.14+ Fix from $1,9502022-08-23 CRITICAL 9.8 CVE-2022-30595 libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. Pillow No fix yet Fix from $2,3002022-05-25 CRITICAL 9.8 CVE-2022-28470 marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. Pypi after 0.13 Fix from $2,3002022-05-08 HIGH 7.6 CVE-2015-20107EPSS 7% In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may… Python 3.10.8+ Fix from $1,9502022-04-13 CRITICAL 9.1 CVE-2022-24303 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. Pillow 9.0.1+ Fix from $2,3002022-03-28 HIGH 7.0 CVE-2022-26488 In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local … Python after 3.10.2 Fix from $1,9502022-03-10 MEDIUM 6.5 CVE-2021-3733 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser)… Python 3.6.14 / 3.7.11+ Fix from $1,6002022-03-10 HIGH 7.5 CVE-2021-3737EPSS 12% A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP … Python 3.6.14 / 3.7.11+ Fix from $1,9502022-03-04 HIGH 7.5 CVE-2022-0391EPSS 8% A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen… Python 3.6.14 / 3.7.11+ Fix from $1,9502022-02-09 CRITICAL 9.8 CVE-2022-22817 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expressi… Pillow 9.0.1+ Fix from $2,3002022-01-10 MEDIUM 6.5 CVE-2022-22815 path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. Pillow 9.0.0+ Fix from $1,6002022-01-10 MEDIUM 6.5 CVE-2022-22816 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. Pillow 9.0.0+ Fix from $1,6002022-01-10 HIGH 7.5 CVE-2021-23437 The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. Pillow 8.3.2+ Fix from $1,9502021-09-03 CRITICAL 9.8 CVE-2021-34552 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert funct… Pillow after 8.2.0 Fix from $2,3002021-07-13 HIGH 7.5 CVE-2021-33503 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg… Urllib3 1.26.5+ Fix from $1,9502021-06-29 CRITICAL 9.1 CVE-2021-25287 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la. Pillow 8.2.0+ Fix from $2,3002021-06-02 CRITICAL 9.1 CVE-2021-25288 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. Pillow 8.2.0+ Fix from $2,3002021-06-02 HIGH 7.5 CVE-2021-28676 An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leadi… Pillow 8.2.0+ Fix from $1,9502021-06-02