Software
python
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
60
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2008-5031 | 10.0 | HIGH | Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the... |
| CVE-2007-4559 | 9.8 | N/A | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overw... |
| CVE-2014-4650 | 9.8 | N/A | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacker... |
| CVE-2016-0718 | 9.8 | N/A | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers... |
| CVE-2016-5636 | 9.8 | N/A | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers... |
| CVE-2016-9063 | 9.8 | N/A | An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. |
| CVE-2017-1000158 | 9.8 | N/A | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer o... |
| CVE-2018-1000802 | 9.8 | N/A | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') v... |
| CVE-2019-10160 | 9.8 | N/A | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and... |
| CVE-2019-12900 | 9.8 | N/A | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. |
| CVE-2019-9636 | 9.8 | N/A | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. Th... |
| CVE-2020-15801 | 9.8 | N/A | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>... |
| CVE-2020-27619 | 9.8 | N/A | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. |
| CVE-2021-29921 | 9.8 | N/A | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attacke... |
| CVE-2021-3177 | 9.8 | N/A | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that... |
| CVE-2022-37454 | 9.8 | N/A | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary c... |
| CVE-2022-48565 | 9.8 | N/A | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid... |
| CVE-2026-7210 | 9.8 | N/A | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash... |
| CVE-2008-1887 | 9.3 | HIGH | Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to th... |
| CVE-2019-9948 | 9.1 | N/A | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist f... |
| CVE-2017-17522 | 8.8 | N/A | Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allo... |
| CVE-2020-1171 | 8.8 | N/A | A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project, aka 'Visual Stud... |
| CVE-2020-29396 | 8.8 | N/A | A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated... |
| CVE-2024-49050 | 8.8 | N/A | Visual Studio Code Python Extension Remote Code Execution Vulnerability |
| CVE-2016-4472 | 8.1 | N/A | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash)... |
| CVE-2019-13404 | 7.8 | N/A | The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code.... |
| CVE-2020-1192 | 7.8 | N/A | A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio C... |
| CVE-2020-15523 | 7.8 | N/A | In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases whe... |
| CVE-2020-17163 | 7.8 | N/A | Visual Studio Code Python Extension Remote Code Execution Vulnerability |
| CVE-2022-42919 | 7.8 | N/A | Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing librar... |
| CVE-2024-9287 | 7.8 | N/A | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allo... |
| CVE-2025-49714 | 7.8 | N/A | Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally. |
| CVE-2015-20107 | 7.6 | N/A | In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow atta... |
| CVE-2004-0150 | 7.5 | HIGH | Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an... |
| CVE-2005-0089 | 7.5 | HIGH | The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register a... |
| CVE-2006-4980 | 7.5 | HIGH | Buffer overflow in the repr function in Python 2.3 through 2.6 before 20060822 allows context-dependent attackers to cause a denial of service and possibly exec... |
| CVE-2007-1657 | 7.5 | HIGH | Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code... |
| CVE-2008-1721 | 7.5 | HIGH | Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed intege... |
| CVE-2008-2315 | 7.5 | HIGH | Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject,... |
| CVE-2008-2316 | 7.5 | HIGH | Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, re... |