Show filters
304 Total Results
Displaying 151-160 of 304
Sort by:
Attacker Value
Unknown
CVE-2020-5310
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
0
Attacker Value
Unknown
CVE-2020-5312
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
0
Attacker Value
Unknown
CVE-2020-5313
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
0
Attacker Value
Unknown
CVE-2014-0161
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2019-14859
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
0
Attacker Value
Unknown
CVE-2016-1000110
Disclosure Date: November 27, 2019 (last updated November 08, 2023)
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
0
Attacker Value
Unknown
CVE-2019-19275
Disclosure Date: November 26, 2019 (last updated November 08, 2023)
typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)
0
Attacker Value
Unknown
CVE-2019-19274
Disclosure Date: November 26, 2019 (last updated November 08, 2023)
typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)
0
Attacker Value
Unknown
CVE-2019-14853
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
0
Attacker Value
Unknown
CVE-2012-5578
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Python keyring has insecure permissions on new databases allowing world-readable files to be created
0