Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

651 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.5%—Ipython NotebookJupyter Notebook29/9/201517/6/2026
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
ModificadaMedia (4.3)2.8%—Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)…
ModificadaMedia (6.8)18%—Google ChromeLibexpat Project LibexpatPythonDebian Linux+923/7/201517/6/2026
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to…
ModificadaMedia (5)2.0%—OpensusePython Pillow1/5/201517/6/2026
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
ModificadaMedia (4.3)2.6%—Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux17/4/201517/6/2026
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a…
ModificadaMedia (6.8)3.4%—Mageia Project MageiaPython RequestsCanonical Ubuntu Linux18/3/201517/6/2026
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
ModificadaMedia (5)4.6%—Python PillowOracle SolarisFedoraproject FedoraOpensuse16/1/201517/6/2026
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
ModificadaMedia (5.8)3.0%—PythonApple MAC OS X12/12/201417/6/2026
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b)…
ModificadaBaja (3.3)0.36%—Python16/11/201417/6/2026
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.
ModificadaMedia (4.4)0.39%—Python-gnupg Project Python-gnupg25/10/201417/6/2026
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
ModificadaMedia (4.6)0.61%—Python-gnupg Project Python-gnupg25/10/201417/6/2026
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than…
ModificadaAlta (7.5)3.4%—Python-gnupg Project Python-gnupg25/10/201417/6/2026
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this…
ModificadaMedia (5)2.0%—OpensusePython Requests15/10/201417/6/2026
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
ModificadaMedia (5)2.2%—Debian LinuxPython RequestsCanonical Ubuntu LinuxMageia15/10/201417/6/2026
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
ModificadaMedia (6.4)5.1%—PythonApple MAC OS X8/10/201417/6/2026
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
ModificadaMedia (4.3)2.0%—Openstack KeystonemiddlewareOpenstack Python-keystoneclient2/10/201417/6/2026
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted…
ModificadaMedia (5)3.4%—Debian Python-imagingPython PillowOpensuse25/8/201417/6/2026
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
ModificadaMedia (6.8)4.7%—OpensuseIpython NotebookMageia7/8/201417/6/2026
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
ModificadaAlta (7.5)2.9%—Vinay Sajip Python-gnupg9/6/201417/6/2026
python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
ModificadaAlta (7.4)95%—OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+125/6/201417/6/2026
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive…
ModificadaMedia (5.8)2.5%—Urbanairship Python-oauth220/5/201416/6/2026
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.
ModificadaMedia (4.3)2.4%—Urbanairship Python-oauth220/5/201416/6/2026
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
ModificadaMedia (4.3)3.3%—Apple MAC OS XPython19/5/201417/6/2026
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input…
ModificadaMedia (6.4)1.8%—Xiaowen Huang Yingzhi Python Programming Language14/5/201416/6/2026
Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI.
ModificadaAlta (10)11%—Python PillowPythonware Python Imaging Library27/4/201417/6/2026
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.