CVE-2017-1000158Critical· 9.8▾ MidnightCPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.9%
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
python < 2.7.15python >= 3.4.0, < 3.4.8python >= 3.5.0, < 3.5.5debian_linux = 7.0debian_linux = 8.0debian_linux = 9.0Upgrade past the affected range:
python 3.5.5Connected by shared product, vendor, weakness, or advisory.
CVE-2018-1000802Critical· 9.8Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Deni…
CVE-2018-1060High· 7.5python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method
CVE-2018-14647High· 7.5Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization
CVE-2021-29921Critical· 9.8In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string
CVE-2022-26488High· 7.0In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured
CVE-2021-3733Medium· 6.5There's a flaw in urllib's AbstractBasicAuthHandler class