Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 5.1% | — | PythonApple MAC OS X | 22/4/2014 | 17/6/2026 | Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function. | |
| Modificada | Baja (2.1) | 0.45% | — | Python PillowPythonware Python Imaging Library | 17/4/2014 | 17/6/2026 | The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes. | |
| Modificada | Media (4.4) | 0.50% | — | Python PillowPythonware Python Imaging Library | 17/4/2014 | 17/6/2026 | The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to… | |
| Modificada | Media (6) | 1.1% | — | Openstack Python-keystoneclient | 15/4/2014 | 17/6/2026 | The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an… | |
| Modificada | Alta (7.5) | 28% | — | PythonApple MAC OS X | 1/3/2014 | 17/6/2026 | Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string. | |
| Modificada | Media (4.3) | 0.90% | — | Python Bugzilla Project Python-bugzillaFedoraproject FedoraOpensuse | 8/2/2014 | 16/6/2026 | python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate. | |
| Modificada | Baja (3.3) | 0.32% | — | Python Pyxdg | 28/1/2014 | 17/6/2026 | Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir… | |
| Modificada | Baja (2.1) | 0.35% | — | Python Rply | 28/1/2014 | 17/6/2026 | The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name. | |
| Modificada | Media (5.5) | 2.1% | — | Openstack Python-keystoneclient | 21/1/2014 | 16/6/2026 | python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires. | |
| Modificada | Media (6.8) | 19% | — | Libexpat Project LibexpatPythonApple IpadosApple Iphone OS+3 | 21/1/2014 | 16/6/2026 | expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML… | |
| Modificada | Media (4.3) | 4.9% | — | PythonCanonical Ubuntu Linux | 9/10/2013 | 16/6/2026 | Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the… | |
| Modificada | Baja (2.1) | 0.37% | — | Openstack Python-keystoneclient | 1/10/2013 | 16/6/2026 | The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process. | |
| Modificada | Media (5.8) | 0.99% | — | Openstack Python GlanceclientOpensuse | 28/8/2013 | 16/6/2026 | The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to… | |
| Modificada | Media (4.3) | 5.3% | — | Canonical Ubuntu LinuxPythonOpensuse | 18/8/2013 | 16/6/2026 | The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate… | |
| Modificada | Media (6.8) | 2.0% | — | Python Setuptools | 6/8/2013 | 16/6/2026 | easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. | |
| Modificada | Baja (2.1) | 0.37% | — | Python Keyring | 30/11/2012 | 16/6/2026 | Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack. | |
| Modificada | Alta (7.3) | 1.2% | — | Activestate Activepython | 11/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Python27 or C:\Python27\Scripts directory, which may be added to the PATH system environment variable… | |
| Modificada | Media (5) | 5.1% | — | Python | 5/10/2012 | 16/6/2026 | Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a… | |
| Modificada | Media (5) | 5.4% | — | Python | 5/10/2012 | 16/6/2026 | SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the… | |
| Modificada | Media (4.3) | 2.5% | — | Python Beaker | 15/9/2012 | 16/6/2026 | Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors. | |
| Modificada | Baja (1.9) | 0.43% | — | Python | 27/8/2012 | 16/6/2026 | Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file. | |
| Modificada | Media (6.4) | 4.5% | — | PythonCanonical Ubuntu LinuxDebian Linux | 14/8/2012 | 16/6/2026 | The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors. | |
| Modificada | Media (4.3) | 5.7% | — | Libexpat Project LibexpatPythonDebian LinuxCanonical Ubuntu Linux+7 | 3/7/2012 | 16/6/2026 | The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value. | |
| Modificada | Baja (2.6) | 3.2% | — | Python | 27/6/2012 | 16/6/2026 | The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against… | |
| Modificada | Media (5.1) | 4.0% | — | Pythonpaste Paste | 1/5/2012 | 16/6/2026 | Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. |