Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2013-1888

Disclosure Date: August 17, 2013 (last updated October 05, 2023)
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
0
Attacker Value
Unknown

CVE-2013-1629

Disclosure Date: August 06, 2013 (last updated October 05, 2023)
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.
0
Attacker Value
Unknown

CVE-2012-1502

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
0