Search CVE reports


Toggle filters

31 – 37 of 37 results


CVE-2008-1721

Medium priority

Some fixes available 5 of 7

Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.

2 affected packages

python2.4, python2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.4 — — — — —
python2.5 — — — — —
Show less packages

CVE-2007-4965

Low priority

Some fixes available 7 of 9

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via...

4 affected packages

python2.2, python2.3, python2.4, python2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.2 — — — — —
python2.3 — — — — —
python2.4 — — — — —
python2.5 — — — — —
Show less packages

CVE-2007-4559

Medium priority

Some fixes available 2 of 21

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR...

16 affected packages

python2.3, python2.4, python2.5, python2.6, python2.7...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.3 — — — — —
python2.4 — — — — —
python2.5 — — — — —
python2.6 — — — — —
python2.7 — — Ignored Not in release Ignored
python3.0 — — — — —
python3.1 — — — — —
python3.10 — — Fixed Not in release Not in release
python3.11 — — Ignored Not in release Not in release
python3.12 — — Not in release Not in release Not in release
python3.4 — — Not in release Not in release Not in release
python3.5 — — Not in release Not in release Not in release
python3.6 — — Not in release Not in release Ignored
python3.7 — — Not in release Not in release Ignored
python3.8 — — Not in release Ignored Ignored
python3.9 — — Not in release Not in release Not in release
Show all 16 packages Show less packages

CVE-2007-2052

Low priority
Fixed

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of...

3 affected packages

python2.3, python2.4, python2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.3 — — — — —
python2.4 — — — — —
python2.5 — — — — —
Show less packages

CVE-2006-4980

Medium priority
Fixed

Buffer overflow in the repr function in Python 2.3 through 2.6 before 20060822 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via crafted wide character UTF-32/UCS-4 strings to...

2 affected packages

python2.3, python2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.3 — — — — —
python2.4 — — — — —
Show less packages

CVE-2005-2491

Medium priority
Fixed

Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in...

6 affected packages

apache2, gnumeric, pcre3, python2.2, python2.3, python2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — —
gnumeric — — — — —
pcre3 — — — — —
python2.2 — — — — —
python2.3 — — — — —
python2.4 — — — — —
Show less packages

CVE-2005-0089

Medium priority
Fixed

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read...

4 affected packages

python2.2, python2.3, python2.4, python2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.2 — — — — —
python2.3 — — — — —
python2.4 — — — — —
python2.5 — — — — —
Show less packages