Search CVE reports


Toggle filters

111 – 120 of 133 results


CVE-2018-20852

Medium priority

Some fixes available 8 of 10

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-10160

Medium priority

Some fixes available 9 of 12

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-9948

Medium priority

Some fixes available 9 of 11

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-9947

Medium priority

Some fixes available 9 of 12

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-9740

Medium priority

Some fixes available 9 of 12

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-9636

Medium priority

Some fixes available 8 of 9

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2019-5010

Low priority

Some fixes available 7 of 8

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service....

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-20406

Low priority
Fixed

Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Not affected
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Not affected
Show less packages

CVE-2018-14647

Medium priority
Fixed

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — Not in release Not affected Not affected Fixed
python3.4 — Not in release Not in release Not in release Not in release
python3.5 — Not in release Not in release Not in release Not in release
python3.6 — Not in release Not in release Not in release Fixed
python3.7 — Not in release Not in release Not in release Fixed
Show less packages

CVE-2018-1000802

Medium priority
Fixed

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result...

5 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 — — — — Fixed
python3.4 — — — — Not in release
python3.5 — — — — Not in release
python3.6 — — — — Not affected
python3.7 — — — — Not affected
Show less packages