Search CVE reports
91 – 100 of 109 results
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 8 of 10
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 9 of 12
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 9 of 11
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering...
5 affected packages
python3.5, python3.6, python2.7, python3.7, python3.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
Some fixes available 9 of 12
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 9 of 12
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument...
5 affected packages
python3.4, python3.5, python2.7, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 8 of 9
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Some fixes available 7 of 8
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service....
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the...
5 affected packages
python3.5, python3.6, python3.7, python2.7, python3.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Not affected |
| python2.7 | — | Not in release | Not affected | Not affected | Not affected |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would...
5 affected packages
python2.7, python3.4, python3.5, python3.6, python3.7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python2.7 | — | Not in release | Not affected | Not affected | Fixed |
| python3.4 | — | Not in release | Not in release | Not in release | Not in release |
| python3.5 | — | Not in release | Not in release | Not in release | Not in release |
| python3.6 | — | Not in release | Not in release | Not in release | Fixed |
| python3.7 | — | Not in release | Not in release | Not in release | Fixed |