CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
SSLContext.wrap_bio() missing validation of server_hostname parameter
Use-after-free of a server-side SSLContext when sni_callback switches contexts
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
tarfile hardlink fallback ignores custom extraction filter rejection via None
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
tarfile extraction filter bypass allows creation of directories outside the destination
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Quadratic Behavior in xml.etree.ElementPath Index Predicates
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Tarfile.extract() doesn't fully respect filter parameter
tarfile opened in streaming mode mishandles EOF
Configuration Injection via Carriage Return (\r) in write() method
tarfile extraction filter bypass allows escaping the destination directory
CPython >3.11 Insecure Input Validation resulting in privilege escalation
bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Potential DoS via quadratic complexity in unicodedata.normalize()
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
BaseCookie.js_output() does not neutralize embedded characters
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
Showing 1 to 25 CVEs · page 1 (more available)