Python
python
268 CVEs • 30 products
Products (30)
Click to collapseToggle
Products (30)
Click to collapse
CVEs (268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. |
3Debian FedoraprojectPython3Debian Linux FedoraPythonNov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests. |
typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpret...Show more |
typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the inte...Show more |
Python keyring has insecure permissions on new databases allowing world-readable files to be created |
2Python Redhat3Enterprise Linux Enterprise Virtualization HypervisorPyxmlNov 21, 2024 Nov 22, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 PyXML: Hash table collisions CPU usage Denial of Service |
4Debian OpensusePython+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial o...Show more |
2Debian Python2Debian Linux KeyringNov 21, 2024 Oct 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python keyring lib before 0.10 created keyring files with world-readable permissions. |
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib...Show more |
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Oct 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the ima...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxJun 17, 2026 Sep 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py i...Show more |
7Canonical DebianFedoraproject+4 more10Communications Operations Monitor Debian LinuxFedora+7 moreJun 17, 2026 Sep 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that u...Show more |
2Libexpat Project Python2Libexpat PythonJun 17, 2026 Sep 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted...Show more |
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to gen...Show more |
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may a...Show more |
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the...Show more |
6Bzip CanonicalDebian+3 more6Bzip2 Debian LinuxFreebsd+3 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. |