Search CVE reports


Toggle filters

121 – 130 of 134 results


CVE-2019-9740

Medium priority

Some fixes available 9 of 12

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-9636

Medium priority

Some fixes available 8 of 9

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-5010

Low priority

Some fixes available 7 of 8

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service....

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-20406

Low priority
Fixed

Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Not affected
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-14647

Medium priority
Fixed

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Fixed
Show less packages

CVE-2018-1000802

Medium priority
Fixed

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — — — — Fixed
python3.4 — — — — Not in release
python3.5 — — — — Not in release
python3.6 — — — — Not affected
python3.7 — — — — Not affected
Show less packages

CVE-2018-1061

Low priority

Some fixes available 5 of 8

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Not affected
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Not affected
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-1060

Low priority

Some fixes available 5 of 8

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Not affected
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Not affected
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-1000117

Medium priority
Not affected

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege....

4 affected packages

python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.4 — — Not in release Not in release Not in release
python3.5 — — Not in release Not in release Not in release
python3.6 — — Not in release Not in release Not affected
python3.7 — — Not in release Not in release Not affected
Show less packages

CVE-2017-18207

Low priority
Ignored

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — — Ignored Ignored Ignored
python3.4 — — Not in release Not in release Not in release
python3.5 — — Not in release Not in release Not in release
python3.6 — — Not in release Not in release Ignored
python3.7 — — Not in release Not in release Ignored
Show less packages