CVE-2020-15523High· 7.8▾ TwilightIn Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.
python >= 3.5.0, < 3.5.10python >= 3.6.0, < 3.6.12python >= 3.7.0, < 3.7.9python >= 3.8.0, < 3.8.4python = 3.8.4python = 3.9.0snapcenterUpgrade past the affected range:
python 3.8.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29921Critical· 9.8In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string
CVE-2022-26488High· 7.0In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured
CVE-2021-3733Medium· 6.5There's a flaw in urllib's AbstractBasicAuthHandler class
CVE-2020-27619Critical· 9.8In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
CVE-2020-26116High· 7.2http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in…
CVE-2020-14422Medium· 5.9Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of…