Search CVE reports


Toggle filters

81 – 88 of 88 results


CVE-2014-9365

Medium priority

Some fixes available 1 of 4

The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust...

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2014-2667

Low priority

Some fixes available 1 of 3

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging...

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 Not affected
python3.2 Not in release
python3.4 Not in release
Show less packages

CVE-2014-7185

Low priority
Fixed

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2014-4616

Low priority

Some fixes available 4 of 5

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx...

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2014-4650

Low priority

Some fixes available 4 of 5

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal...

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2013-7338

Low priority
Ignored

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3)...

6 affected packages

python2.6, python2.7, python3.1, python3.2, python3.3, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.6
python2.7
python3.1
python3.2
python3.3
python3.4
Show less packages

CVE-2014-1912

Medium priority

Some fixes available 8 of 9

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

6 affected packages

python2.6, python2.7, python3.1, python3.2, python3.3, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.6
python2.7
python3.1
python3.2
python3.3
python3.4
Show less packages

CVE-2007-4559

Medium priority

Some fixes available 2 of 30

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR...

16 affected packages

python2.3, python2.4, python2.5, python2.6, python2.7...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.3
python2.4
python2.5
python2.6
python2.7 Ignored Ignored Ignored
python3.0
python3.1
python3.10 Fixed Not in release Not in release
python3.11 Ignored Not in release Not in release
python3.12 Not in release Not in release Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Ignored
python3.7 Not in release Not in release Ignored
python3.8 Not in release Ignored Ignored
python3.9 Not in release Ignored Not in release
Show all 16 packages Show less packages