Python
python
268 CVEs • 30 products
Products (30)
Click to collapseToggle
Products (30)
Click to collapse
CVEs (268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. |
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarou...Show more |
3Fedoraproject NetappPython5Active Iq Unified Manager FedoraOntap Select Deploy Administration Utility+2 moreNov 3, 2025 Apr 13, 2022 N/A· v4 7.6 HIGH· v3 8.0 HIGH· v2 In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call m...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 28, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. |
11Apple AzulDebian+8 more27Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+24 moreJul 14, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
2Netapp Python3Active Iq Unified Manager Ontap Select Deploy Administration UtilityPythonJun 17, 2026 Mar 10, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To...Show more |
4Fedoraproject NetappPython+1 more20Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+17 moreJun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReD...Show more |
6Canonical FedoraprojectNetapp+3 more17Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 moreJun 17, 2026 Mar 4, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more |
4Fedoraproject NetappOracle+1 more10Active Iq Unified Manager FedoraHci+7 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input...Show more |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. |
2Microco Python2Bluemonday PybluemondayJun 17, 2026 Oct 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Sep 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. |
3Debian FedoraprojectPython3Debian Linux FedoraPillowJun 17, 2026 Jul 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. |
3Fedoraproject OraclePython5Enterprise Manager Ops Center FedoraInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jun 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a larg...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jun 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of ac...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jun 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load. |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jun 2, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. |