← Back

Python

python

268 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Python
python
Pillow
pillow
Urllib3
urllib3
Requests
requests
Setuptools
setuptools
Keyring
keyring
Pyxdg
pyxdg
Typed Ast
typed_ast
Black
black
Virtualenv
virtualenv
Beaker
beaker
Rply
rply
Rsa
rsa
Tgcaptcha2
tgcaptcha2
Hpack
hpack
Hyper
hyper
Openpyxl
openpyxl
Tablib
tablib
Pypiserver
pypiserver
Python Gnupg
python-gnupg
Novajoin
novajoin
Pyxml
pyxml
Py Bcrypt
py-bcrypt
Jw.util
jw.util
Pybluemonday
pybluemonday
Tkvideoplayer
tkvideoplayer
Pypi
pypi
Pymanager
pymanager
Cpython
cpython

CVEs (268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Python
1Python
May 6, 2026
Jun 7, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted cert...Show more
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.Show less
9Apple
CanonicalDebian+6 more
14Debian Linux
FirefoxLeap+11 more
May 6, 2026
May 26, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
1Python
1Pillow
May 6, 2026
Apr 13, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-bas...Show more
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.Show less
3Debian
PythonPython Imaging Project
3Debian Linux
PillowPython Imaging
May 6, 2026
Apr 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD...Show more
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.Show less
2Debian
Python
2Debian Linux
Pillow
May 6, 2026
Apr 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
2Debian
Python
2Debian Linux
Pillow
May 6, 2026
Apr 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
3Fedoraproject
OpensusePython
4Fedora
LeapOpensuse+1 more
May 6, 2026
Jan 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
1Python
1Python
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It...Show more
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."Show less
8Canonical
DebianGoogle+5 more
13Chrome
Debian LinuxLeap+10 more
May 6, 2026
Jul 23, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer ove...Show more
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.Show less
2Opensuse
Python
2Opensuse
Pillow
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
3Canonical
Mageia ProjectPython
3Mageia
RequestsUbuntu Linux
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
4Fedoraproject
OpensuseOracle+1 more
4Fedora
OpensusePillow+1 more
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
2Apple
Python
2Mac Os X
Python
May 6, 2026
Dec 12, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate again...Show more
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Python
1Python
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
3.3 LOW· v2
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveragin...Show more
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.Show less
2Opensuse
Python
2Opensuse
Requests
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
4Canonical
DebianMageia+1 more
4Debian Linux
MageiaRequests+1 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
2Apple
Python
2Mac Os X
Python
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
3Debian
OpensusePython
3Opensuse
PillowPython Imaging
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
9Fedoraproject
Filezilla ProjectMariadb+6 more
16Application Processing Engine Firmware
Cp1543 1 FirmwareEnterprise Linux+13 more
May 6, 2026
Jun 5, 2014
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.Show less
2Apple
Python
2Mac Os X
Python
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easie...Show more
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.Show less