CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
SSLContext.wrap_bio() missing validation of server_hostname parameter
Use-after-free of a server-side SSLContext when sni_callback switches contexts
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
tarfile hardlink fallback ignores custom extraction filter rejection via None
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
tarfile extraction filter bypass allows creation of directories outside the destination
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Quadratic Behavior in xml.etree.ElementPath Index Predicates
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Pillow GdImageFile decompression bomb protection bypass
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Showing 1 to 25 CVEs · page 1 (more available)