Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.77% | — | Python-markdown2 Project Python-markdown2 | 15/1/2020 | 16/6/2026 | python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues. | |
| Modificada | Alta (7.5) | 2.1% | — | Python PillowDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 5/1/2020 | 17/6/2026 | There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python… | |
| Modificada | Alta (7.1) | 2.8% | — | Python PillowCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 3/1/2020 | 17/6/2026 | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. | |
| Modificada | Crítica (9.8) | 3.7% | — | Python PillowCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 3/1/2020 | 17/6/2026 | libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. | |
| Modificada | Crítica (9.8) | 4.2% | — | Python PillowCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 3/1/2020 | 17/6/2026 | libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. | |
| Modificada | Alta (8.8) | 2.0% | — | Python PillowCanonical Ubuntu LinuxFedoraproject Fedora | 3/1/2020 | 17/6/2026 | libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. | |
| Modificada | Media (5.9) | 0.42% | — | Ovirt-engine-sdk-python Project Ovirt-engine-sdk-python | 2/1/2020 | 17/6/2026 | ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid… | |
| Modificada | Crítica (9.1) | 1.5% | — | Python-ecdsa Project Python-ecdsaRedhat Ceph StorageRedhat OpenstackRedhat Virtualization | 2/1/2020 | 17/6/2026 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create… | |
| Modificada | Crítica (9.8) | 2.0% | — | Openstack Python-keystoneclientRedhat OpenstackDebian Linux | 10/12/2019 | 16/6/2026 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass | |
| Modificada | Crítica (9.8) | 2.1% | — | Openstack Python-keystoneclientRedhat OpenstackFedoraproject FedoraDebian Linux | 10/12/2019 | 16/6/2026 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass | |
| Modificada | Media (6.1) | 4.5% | — | PythonDebian LinuxFedoraproject Fedora | 27/11/2019 | 17/6/2026 | The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests. | |
| Modificada | Alta (7.5) | 3.3% | — | Python Typed AST | 26/11/2019 | 17/6/2026 | typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not… | |
| Modificada | Alta (7.5) | 3.3% | — | Python Typed AST | 26/11/2019 | 17/6/2026 | typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does… | |
| Modificada | Alta (7.5) | 2.4% | — | Python-ecdsa Project Python-ecdsa | 26/11/2019 | 17/6/2026 | An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service. | |
| Modificada | Media (6.2) | 0.44% | — | Python Keyring | 25/11/2019 | 16/6/2026 | Python keyring has insecure permissions on new databases allowing world-readable files to be created | |
| Modificada | Alta (7.5) | 1.9% | — | Python PyxmlRedhat Enterprise Virtualization HypervisorRedhat Enterprise Linux | 22/11/2019 | 16/6/2026 | PyXML: Hash table collisions CPU usage Denial of Service | |
| Modificada | Alta (7.5) | 21% | — | PythonOpensuse LeapDebian LinuxRedhat Enterprise Linux+3 | 31/10/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger… | |
| Modificada | Crítica (9.1) | 1.4% | — | Python-docutils Project Python-docutilsDebian Linux | 31/10/2019 | 16/6/2026 | python-docutils allows insecure usage of temporary files | |
| Modificada | Alta (7.5) | 1.8% | — | Python KeyringDebian Linux | 28/10/2019 | 16/6/2026 | Python keyring lib before 0.10 created keyring files with world-readable permissions. | |
| Modificada | Media (6.1) | 3.5% | — | Python | 23/10/2019 | 17/6/2026 | An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP… | |
| Modificada | Alta (7.5) | 4.7% | — | Python | 12/10/2019 | 17/6/2026 | library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross application domains, and thus it is likely that security-relevant code… | |
| Modificada | Alta (7.5) | 3.1% | — | Python PillowFedoraproject Fedora | 4/10/2019 | 17/6/2026 | An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. | |
| Modificada | Media (6.1) | 4.7% | — | PythonDebian LinuxCanonical Ubuntu Linux | 28/9/2019 | 17/6/2026 | The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be… | |
| Modificada | Alta (7.8) | 0.36% | — | Pam-python Project Pam-pythonDebian LinuxCanonical Ubuntu Linux | 24/9/2019 | 17/6/2026 | pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups. | |
| Modificada | Alta (7.5) | 5.4% | — | PythonFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+6 | 6/9/2019 | 17/6/2026 | An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could… |