Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-10160EPSS 5% A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.… Python 2.7.17 / 3.5.8+ Fix from $2,3002019-06-07 HIGH 7.5 CVE-2019-12761 A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_… Pyxdg 0.26+ Fix from $1,9502019-06-06 HIGH 7.5 CVE-2019-11324 The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA c… Urllib3 1.24.2+ Fix from $1,9502019-04-18 MEDIUM 6.1 CVE-2019-11236 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. Urllib3 after 1.24.2 Fix from $1,6002019-04-15 CRITICAL 9.1 CVE-2019-9948EPSS 12% urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that … Python 2.7.17 / 3.5.8+ Fix from $2,3002019-03-23 MEDIUM 6.1 CVE-2019-9947EPSS 5% An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker co… Python 2.7.17 / 3.5.8+ Fix from $1,6002019-03-23 HIGH 7.5 CVE-2019-6690EPSS 9% python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase… Python Gnupg No fix yet Fix from $1,9502019-03-21 MEDIUM 6.1 CVE-2019-9740EPSS 5% An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker co… Python 2.7.17 / 3.5.8+ Fix from $1,6002019-03-13 CRITICAL 9.8 CVE-2019-9636EPSS 9% Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normal… Python 2.7.17 / 3.4.10+ Fix from $2,3002019-03-08 MEDIUM 6.1 CVE-2019-6802 CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. Pypiserver after 1.2.5 Fix from $1,6002019-01-25 HIGH 7.5 CVE-2018-20406EPSS 6% Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size"… Python 3.7.1+ Fix from $1,9502018-12-23 CRITICAL 9.8 CVE-2018-20060 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho… Urllib3 1.23+ Fix from $2,3002018-12-11 HIGH 7.5 CVE-2018-18074EPSS 7% The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect… Requests 2.20.0+ Fix from $1,9502018-10-09 HIGH 7.5 CVE-2018-14647EPSS 11% Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service… Python after 3.6.6 Fix from $1,9502018-09-25 HIGH 7.5 CVE-2018-1061 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An… Python 2.7.15 / 3.4.9+ Fix from $1,9502018-06-19 HIGH 7.5 CVE-2018-1060EPSS 5% python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker… Python 2.7.15 / 3.4.9+ Fix from $1,9502018-06-18 MEDIUM 6.7 CVE-2018-1000117 Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windo… Python 3.4.9 / 3.5.6+ Fix from $1,6002018-03-07 MEDIUM 6.5 CVE-2017-18207 The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to caus… Python after 3.6.4 Fix from $1,6002018-03-01 HIGH 8.8 CVE-2017-17522 Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which… Python after 3.6.3 Fix from $1,9502017-12-14 CRITICAL 9.8 CVE-2017-1000158EPSS 8% CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-bas… Python 2.7.15 / 3.4.8+ Fix from $2,3002017-11-17 MEDIUM 5.9 CVE-2014-4616EPSS 8% Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attac… Python 2.6.1 / 2.7.7+ Fix from $1,6002017-08-24 HIGH 7.5 CVE-2017-9233EPSS 9% XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop usi… Python 2.7.15 / 3.3.7+ Fix from $1,9502017-07-25 CRITICAL 9.8 CVE-2017-2810 An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python comma… Tablib No fix yet Fix from $2,3002017-06-14 MEDIUM 5.5 CVE-2016-3076 Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memor… Pillow Mitigation only Fix from $1,6002017-04-24 HIGH 8.2 CVE-2017-5992 Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document. Openpyxl Patch available Fix from $1,9502017-02-15 HIGH 7.5 CVE-2016-6580 A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having… Python Priority Library Mitigation only Fix from $1,9502017-01-10 HIGH 7.5 CVE-2016-6581 A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attac… Hpack Mitigation only Fix from $1,9502017-01-10 HIGH 7.8 CVE-2016-9190 Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure … Pillow after 3.3.1 Fix from $1,9502016-11-04 MEDIUM 5.5 CVE-2016-9189 Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Int… Pillow after 3.3.1 Fix from $1,6002016-11-04 HIGH 7.5 CVE-2016-1000032 TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times. Tgcaptcha2 Mitigation only Fix from $1,9502016-10-25