Vulnerabilities > Python Software Foundation

DATE CVE VULNERABILITY TITLE RISK
2009-01-28 CVE-2008-5983 Unspecified vulnerability in Python Software Foundation Python
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
6.9
2008-11-01 CVE-2008-4864 Numeric Errors vulnerability in Python Software Foundation Python
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow, a different vulnerability than CVE-2007-4965 and CVE-2008-1679.
network
low complexity
python-software-foundation CWE-189
7.5
2008-09-18 CVE-2008-4108 Link Following vulnerability in Python Software Foundation Python 2.4.5
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file.
local
low complexity
python-software-foundation CWE-59
7.2
2008-08-01 CVE-2008-2315 Numeric Errors vulnerability in Python Software Foundation Python
Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.
network
low complexity
python-software-foundation CWE-189
7.5
2008-08-01 CVE-2008-2316 Numeric Errors vulnerability in Python Software Foundation Python
Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to "partial hashlib hashing of data exceeding 4GB."
network
low complexity
python-software-foundation CWE-189
7.5
2008-08-01 CVE-2008-3142 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Python Software Foundation Python
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.
network
low complexity
python-software-foundation CWE-119
7.5
2008-08-01 CVE-2008-3143 Numeric Errors vulnerability in Python Software Foundation Python
Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."
network
low complexity
python-software-foundation CWE-189
7.5
2008-08-01 CVE-2008-3144 Numeric Errors vulnerability in Python Software Foundation Python
Multiple integer overflows in the PyOS_vsnprintf function in Python/mysnprintf.c in Python 2.5.2 and earlier allow context-dependent attackers to cause a denial of service (memory corruption) or have unspecified other impact via crafted input to string formatting operations.
network
low complexity
python-software-foundation CWE-189
5.0
2008-04-22 CVE-2008-1679 Numeric Errors vulnerability in Python Software Foundation Python 2.4
Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows.
6.8
2008-04-18 CVE-2008-1887 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Python Software Foundation Python
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
9.3