Search CVE reports


Toggle filters

91 – 100 of 110 results


CVE-2013-7440

Low priority
Ignored

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2013-7338

Low priority
Ignored

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3)...

6 affected packages

python2.6, python2.7, python3.1, python3.2, python3.3, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.6
python2.7
python3.1
python3.2
python3.3
python3.4
Show less packages

CVE-2013-7040

Low priority
Ignored

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for...

5 affected packages

python2.6, python2.7, python3.1, python3.2, python3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.6
python2.7
python3.1
python3.2
python3.3
Show less packages

CVE-2013-4238

Medium priority

Some fixes available 8 of 9

The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle...

5 affected packages

python2.6, python2.7, python3.1, python3.2, python3.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.6
python2.7
python3.1
python3.2
python3.3
Show less packages

CVE-2013-2099

Low priority

Some fixes available 5 of 41

Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote...

10 affected packages

bzr, w3af, linkchecker, python-tornado, python-urllib3...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bzr Not affected Not affected Not affected Not affected
w3af Not in release Not in release Not in release Not in release
linkchecker Not affected Not affected Not in release Not affected
python-tornado Not affected Not affected Not affected Not affected
python-urllib3 Not affected Not affected Not affected Not affected
python2.7 Not in release Not affected Not affected Not affected
python3.1 Not in release Not in release Not in release Not in release
python3.2 Not in release Not in release Not in release Not in release
python3.3 Not in release Not in release Not in release Not in release
zeroinstall-injector Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2013-1753

Medium priority
Fixed

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2013-1752

Low priority

Some fixes available 4 of 8

Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4,...

3 affected packages

python2.7, python3.2, python3.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7
python3.2
python3.4
Show less packages

CVE-2012-2639

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4940. Reason: This candidate is a reservation duplicate of CVE-2011-4940. Notes: All CVE users should reference CVE-2011-4940 instead of this candidate. ...

3 affected packages

python2.5, python2.6, python2.7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.5
python2.6
python2.7
Show less packages

CVE-2012-1150

Medium priority

Some fixes available 9 of 14

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause...

6 affected packages

python2.4, python2.5, python2.6, python2.7, python3.1, python3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.4
python2.5
python2.6
python2.7
python3.1
python3.2
Show less packages

CVE-2012-0845

Low priority

Some fixes available 11 of 14

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an...

6 affected packages

python2.4, python2.5, python2.6, python2.7, python3.1, python3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.4
python2.5
python2.6
python2.7
python3.1
python3.2
Show less packages