CVEs (139)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical FedoraprojectNetapp+3 more17Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 moreJun 17, 2026 Mar 4, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more |
4Fedoraproject NetappOracle+1 more10Active Iq Unified Manager FedoraHci+7 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input...Show more |
6Debian FedoraprojectNetapp+3 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionDebian Linux+7 moreJun 17, 2026 May 20, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more |
2Oracle Python6Communications Cloud Native Core Automated Test Suite Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Slice Selection Function+3 moreJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. |
6Debian DjangoprojectFedoraproject+3 more12Cloud Backup Communications Offline Mediation ControllerCommunications Pricing Design Center+9 moreJun 17, 2026 Feb 15, 2021 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.pars...Show more |
5Debian FedoraprojectNetapp+2 more10Active Iq Unified Manager Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Offline Mediation Controller+7 moreJun 17, 2026 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demons...Show more |
3Fedoraproject OraclePython3Communications Cloud Native Core Network Function Cloud Native Environment FedoraPythonJun 17, 2026 Oct 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. |
7Canonical DebianFedoraproject+4 more8Debian Linux FedoraHci Storage Node+5 moreJun 17, 2026 Sep 27, 2020 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF cont...Show more |
2Netapp Python2Max Data PythonJun 17, 2026 Jul 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected. |
7Canonical DebianFedoraproject+4 more8Active Iq Unified Manager Cloud Volumes Ontap MediatorDebian Linux+5 moreJun 17, 2026 Jul 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation. |
2Netapp Python2Python SnapcenterJun 17, 2026 Jul 4, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs...Show more |
4Fedoraproject OpensuseOracle+1 more4Enterprise Manager Ops Center FedoraLeap+1 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more |
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request. |
2Python Redhat3Enterprise Linux PythonSoftware CollectionsNov 21, 2024 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal...Show more |
3Canonical NetappPython3Active Iq Unified Manager PythonUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jan 30, 2020 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of...Show more |
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and...Show more |
3Debian FedoraprojectPython3Debian Linux FedoraPythonNov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests. |
4Debian OpensusePython+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial o...Show more |
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib...Show more |