Search CVE reports
1 – 10 of 28 results
Some fixes available 2 of 3
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not...
7 affected packages
python2.6, python2.7, python3.2, python3.4, python3.5...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | Not in release |
python2.7 | — | — | — | Not affected |
python3.2 | — | — | — | Not in release |
python3.4 | — | — | — | Not in release |
python3.5 | — | — | — | Not in release |
python3.6 | — | — | — | Not affected |
python3.7 | — | — | — | Not affected |
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted...
8 affected packages
jython, python2.6, python2.7, python3.2, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jython | — | Not affected | Not affected | Not affected |
python2.6 | — | Not in release | Not in release | Not in release |
python2.7 | — | Not affected | Not affected | Not affected |
python3.2 | — | Not in release | Not in release | Not in release |
python3.4 | — | Not in release | Not in release | Not in release |
python3.5 | — | Not in release | Not in release | Not in release |
python3.6 | — | Not in release | Not in release | Not affected |
python3.7 | — | Not in release | Not in release | Not affected |
Some fixes available 8 of 9
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
6 affected packages
python2.6, python2.7, python3.1, python3.2, python3.3, python3.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | — |
python2.7 | — | — | — | — |
python3.1 | — | — | — | — |
python3.2 | — | — | — | — |
python3.3 | — | — | — | — |
python3.4 | — | — | — | — |
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3)...
6 affected packages
python2.6, python2.7, python3.1, python3.2, python3.3, python3.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | — |
python2.7 | — | — | — | — |
python3.1 | — | — | — | — |
python3.2 | — | — | — | — |
python3.3 | — | — | — | — |
python3.4 | — | — | — | — |
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for...
5 affected packages
python2.6, python2.7, python3.1, python3.2, python3.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | — |
python2.7 | — | — | — | — |
python3.1 | — | — | — | — |
python3.2 | — | — | — | — |
python3.3 | — | — | — | — |
Some fixes available 8 of 9
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle...
5 affected packages
python2.6, python2.7, python3.1, python3.2, python3.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | — |
python2.7 | — | — | — | — |
python3.1 | — | — | — | — |
python3.2 | — | — | — | — |
python3.3 | — | — | — | — |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2099. Reason: This candidate is a duplicate of CVE-2013-2099. Notes: All CVE users should reference CVE-2013-2099 instead of this candidate. All references...
1 affected package
python2.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.6 | — | — | — | — |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
40 affected packages
tdom, apache2, apr-util, audacity, ayttm...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
tdom | — | — | — | — |
apache2 | — | — | — | — |
apr-util | — | — | — | — |
audacity | — | — | — | — |
ayttm | — | — | — | — |
cableswig | — | — | — | — |
cadaver | — | — | — | — |
celementtree | — | — | — | — |
cmake | — | — | — | — |
coin3 | — | — | — | — |
expat | — | — | — | — |
gdcm | — | — | — | — |
ghostscript | — | — | — | — |
grmonitor | — | — | — | — |
insighttoolkit | — | — | — | — |
kompozer | — | — | — | — |
libparagui1.1 | — | — | — | — |
matanza | — | — | — | — |
paraview | — | — | — | — |
poco | — | — | — | — |
python-xml | — | — | — | — |
python2.4 | — | — | — | — |
python2.5 | — | — | — | — |
python2.6 | — | — | — | — |
simgear | — | — | — | — |
sitecopy | — | — | — | — |
smart | — | — | — | — |
swish-e | — | — | — | — |
texlive-bin | — | — | — | — |
tla | — | — | — | — |
vnc4 | — | — | — | — |
vtk | — | — | — | — |
w3c-libwww | — | — | — | — |
wbxml2 | — | — | — | — |
wxwidgets2.6 | — | — | — | — |
wxwidgets2.8 | — | — | — | — |
wxwindows2.4 | — | — | — | — |
xmlrpc-c | — | — | — | — |
xotcl | — | — | — | — |
xulrunner | — | — | — | — |
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption),...
40 affected packages
apache2, apr-util, audacity, ayttm, cableswig...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
apache2 | — | — | — | — |
apr-util | — | — | — | — |
audacity | — | — | — | — |
ayttm | — | — | — | — |
cableswig | — | — | — | — |
cadaver | — | — | — | — |
celementtree | — | — | — | — |
cmake | — | — | — | — |
coin3 | — | — | — | — |
expat | — | — | — | — |
gdcm | — | — | — | — |
ghostscript | — | — | — | — |
grmonitor | — | — | — | — |
insighttoolkit | — | — | — | — |
kompozer | — | — | — | — |
libparagui1.1 | — | — | — | — |
matanza | — | — | — | — |
paraview | — | — | — | — |
poco | — | — | — | — |
python-xml | — | — | — | — |
python2.4 | — | — | — | — |
python2.5 | — | — | — | — |
python2.6 | — | — | — | — |
simgear | — | — | — | — |
sitecopy | — | — | — | — |
smart | — | — | — | — |
swish-e | — | — | — | — |
tdom | — | — | — | — |
texlive-bin | — | — | — | — |
tla | — | — | — | — |
vnc4 | — | — | — | — |
vtk | — | — | — | — |
w3c-libwww | — | — | — | — |
wbxml2 | — | — | — | — |
wxwidgets2.6 | — | — | — | — |
wxwidgets2.8 | — | — | — | — |
wxwindows2.4 | — | — | — | — |
xmlrpc-c | — | — | — | — |
xotcl | — | — | — | — |
xulrunner | — | — | — | — |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4940. Reason: This candidate is a reservation duplicate of CVE-2011-4940. Notes: All CVE users should reference CVE-2011-4940 instead of this candidate. ...
3 affected packages
python2.5, python2.6, python2.7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
python2.5 | — | — | — | — |
python2.6 | — | — | — | — |
python2.7 | — | — | — | — |