CVE-2019-5010High· 7.5▾ MidnightPoC availableAn exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An att…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 4.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
21%
1 GitHub repo (last check)
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
python >= 2.7.0, < 2.7.16python >= 3.4.0, < 3.4.10python >= 3.5.0, < 3.5.7python >= 3.6.0, < 3.6.9python >= 3.7.0, < 3.7.3leap = 15.1debian_linux = 9.0enterprise_linux = 8.0enterprise_linux_eus = 8.1enterprise_linux_eus = 8.2enterprise_linux_eus = 8.4enterprise_linux_eus = 8.6enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6Upgrade past the affected range:
python 3.7.3Connected by shared product, vendor, weakness, or advisory.
CVE-2019-9948Critical· 9.1urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/…
CVE-2018-14647High· 7.5Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization
CVE-2019-16056High· 7.5An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4
CVE-2019-16935Medium· 6.1The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field
CVE-2019-9947Medium· 6.1An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3
CVE-2019-9636Critical· 9.8Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization