Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Python-jose Project Python-jose | 23/1/2017 | 17/6/2026 | python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys. | |
| Modificada | Baja (3.7) | 0.75% | — | Python Urllib3 | 11/1/2017 | 17/6/2026 | Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability… | |
| Modificada | Alta (7.5) | 1.8% | — | Python HpackPython Hyper | 10/1/2017 | 17/6/2026 | A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table… | |
| Modificada | Alta (7.5) | 1.8% | — | Python Priority Library | 10/1/2017 | 17/6/2026 | A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream,… | |
| Modificada | Alta (8.8) | 2.4% | — | Python-openxml Project Python-docx | 21/12/2016 | 17/6/2026 | python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document. | |
| Modificada | Alta (7.8) | 1.9% | — | Python PillowDebian Linux | 4/11/2016 | 17/6/2026 | Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. | |
| Modificada | Media (5.5) | 1.9% | — | Python PillowDebian Linux | 4/11/2016 | 17/6/2026 | Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component. | |
| Modificada | Media (5.6) | 2.2% | — | Oracle Mysql Connector/python | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python. | |
| Modificada | Alta (7.5) | 1.3% | — | Python Tgcaptcha2 | 25/10/2016 | 17/6/2026 | TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times. | |
| Modificada | Crítica (9.8) | 3.2% | — | Openstack Mitaka-muranoOpenstack MuranoOpenstack Murano-dashboardOpenstack Python-muranoclient | 26/9/2016 | 17/6/2026 | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows… | |
| Modificada | Media (6.1) | 9.9% | — | Python | 2/9/2016 | 17/6/2026 | CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL. | |
| Modificada | Crítica (9.8) | 25% | — | Python | 2/9/2016 | 17/6/2026 | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 15% | — | Python | 2/9/2016 | 17/6/2026 | The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS… | |
| Modificada | Alta (7.5) | 95% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+5 | 1/9/2016 | 17/6/2026 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated… | |
| Modificada | Alta (8.1) | 12% | — | Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython | 30/6/2016 | 17/6/2026 | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716. | |
| Modificada | Media (6.5) | 16% | — | Bzip2Python | 30/6/2016 | 17/6/2026 | Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block. | |
| Modificada | Media (5.9) | 1.9% | — | Python | 7/6/2016 | 17/6/2026 | The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate. | |
| Modificada | Crítica (9.8) | 13% | — | Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+10 | 26/5/2016 | 17/6/2026 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
| Modificada | Crítica (9.8) | 7.9% | — | Python Pillow | 13/4/2016 | 17/6/2026 | Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 4.0% | — | Python PillowPython Imaging Project Python ImagingDebian Linux | 13/4/2016 | 17/6/2026 | Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file. | |
| Modificada | Media (6.5) | 2.5% | — | Python PillowDebian Linux | 13/4/2016 | 17/6/2026 | Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file. | |
| Modificada | Media (6.5) | 2.6% | — | Python PillowDebian Linux | 13/4/2016 | 17/6/2026 | Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file. | |
| Modificada | Media (5.3) | 7.1% | — | Python RSAFedoraproject FedoraOpensuse LeapOpensuse | 13/1/2016 | 17/6/2026 | The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack. | |
| Modificada | Alta (7.2) | 0.59% | — | Python | 6/10/2015 | 17/6/2026 | Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this… | |
| Modificada | Media (6.8) | 2.5% | — | Ipython NotebookJupyter Notebook | 29/9/2015 | 17/6/2026 | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types. |