Python

Latest version: v0.9.8

Vulnerabilities (155)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2024-4032 71783

The “ipaddress” module contained incorrect information about whether …

  • <3.8.20
  • >=3.9.0a0,<3.9.20
  • >=3.10.0a0,<3.10.15
  • >=3.11.0a0,<3.11.10
  • >=3.12.0a0,<3.12.4
  • >=3.13.0a0,<3.13.0a6
- -
CVE-2020-8492 45696

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7…

  • >=3.6.0a0,<3.6.11
  • >=3.7.0a0,<3.7.7
  • >=3.8.0a0,<3.8.2
  • >=3.9.0a0,<3.9.0a6
  • <2.7.17
  • >=3.0.0a0,<3.5.10
MEDIUM 6.5
CVE-2019-17514 45678

Python versions 2.7.16, 3.4.10, 3.5.7, 3.6.7, 3.7.1 and 3.8.0 include…

  • <2.7.16
  • >=3.0.0a0,<3.4.10
  • >=3.5.0a0,<3.5.7
  • >=3.6.0a0,<3.6.7
  • >=3.7.0a0,<3.7.1
  • >=3.8.0a0,<3.8.0
HIGH 7.5
CVE-2022-45061 51789

Python 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16 include a fix for C…

  • <3.7.16
  • >=3.8.0a0,<3.8.16
  • >=3.9.0a0,<3.9.16
  • >=3.10.0a0,<3.10.9
  • >=3.11.0a0,<3.11.1
HIGH 7.5
CVE-2020-10735 50958

A flaw was found in python. In algorithms with quadratic time complex…

  • <3.7.14
  • >=3.8.0a0,<3.8.14
  • >=3.9.0a0,<3.9.14
  • >=3.10.0a0,<3.10.7
  • >=3.11.0a0,<3.11.0rc1
HIGH 7.5
CVE-2022-48564 60629

Python 3.6.13, 3.7.10, 3.8.7 and 3.9.1 include a fix for CVE-2022-485…

  • >=3.7.0a1,<3.7.10
  • >=3.8.0a1,<3.8.7rc1
  • >=3.9.0a1,<3.9.1rc1
  • ==3.10.0a1
  • >=3.4.0a1,<3.6.13
MEDIUM 6.5
CVE-2022-48566 60631

Python 3.6.13, 3.7.10, 3.8.7, 3.9.1 and 3.10.0a3 include a fix for CV…

  • >=3.7.0a1,<3.7.10
  • >=3.10.0a1,<3.10.0a3
  • >=3.8.0a1,<3.8.7
  • >=3.9.0a1,<3.9.1
  • <3.6.13
MEDIUM 5.9
CVE-2022-48565 60630

Python 3.6.13, 3.7.10, 3.8.7 and 3.9.1 include a fix for CVE-2022-485…

  • >=3.7.0a1,<3.7.10
  • ==3.10.0a1
  • <3.6.13
  • >=3.8.0a1,<3.8.7
  • >=3.9.0a1,<3.9.1
CRITICAL 9.8
PVE-2021-42379 45705

Python versions 3.6.15, 3.7.12, 3.8.12, 3.9.7 and 3.10.0rc2 fix multi…

  • <3.6.15
  • >=3.7.0a0,<3.7.12
  • >=3.8.0a0,<3.8.12
  • >=3.9.0a0,<3.9.7
  • >=3.10.0a0,<3.10.0rc2
HIDDEN X.Y
CVE-2021-3737 45703

A flaw was found in python. An improperly handled HTTP response in th…

  • <3.6.14
  • >=3.7.0a0,<3.7.11
  • >=3.8.0a0,<3.8.11
  • >=3.9.0a0,<3.9.6
  • >=3.10.0a0,<3.10.0b2
HIGH 7.5
CVE-2022-0391 45247

Python versions 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14 include a …

  • <3.6.14
  • >=3.7.0a0,<3.7.11
  • >=3.8.0a0,<3.8.11
  • >=3.9.0a0,<3.9.5
  • >=3.10.0a0,<3.10.0b1
HIGH 7.5
CVE-2021-3733 45815

Python versions 3.6.14, 3.7.11, 3.8.10, 3.9.5 and 3.10.0 include a fi…

  • <3.6.14
  • >=3.7.0a0,<3.7.11
  • >=3.8.0a0,<3.8.10
  • >=3.9.0a0,<3.9.5
  • >=3.10.0a0,<3.10.0
MEDIUM 6.5
PVE-2021-42385 45702

Python versions 3.6.13, 3.7.10, 3.8.7, 3.9.2 and 3.10.0a4 use CRYPTO_…

  • <3.6.13
  • >=3.7.0a0,<3.7.10
  • >=3.8.0a0,<3.8.7
  • >=3.9.0a0,<3.9.2
  • >=3.10.0a0,<3.10.0a4
HIDDEN X.Y
CVE-2021-3426 45723

Python versions 3.6.13, 3.7.10, 3.8.9, 3.9.3 and 3.10.0a7 include a f…

  • >=3.6.0,<3.6.13
  • >=3.7.0,<3.7.10
  • >=3.8.0,<3.8.9
  • >=3.9.0,<3.9.3
  • >=3.10.0,<3.10.0a7
MEDIUM 5.7
CVE-2020-14422 45698

Python versions 3.5.10rc1, 3.6.12, 3.7.9, 3.8.4 and 3.9.0b4 include a…

  • <3.5.10rc1
  • >=3.6.0a0,<3.6.12
  • >=3.7.0a0,<3.7.9
  • >=3.8.0a0,<3.8.4
  • >=3.9.0a0,<3.9.0b4
MEDIUM 5.9
CVE-2020-26116 45697

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x b…

  • <3.5.10
  • >=3.6.0a0,<3.6.12
  • >=3.7.0a0,<3.7.9
  • >=3.8.0a0,<3.8.5
  • >=3.9.0a0,<3.9.0b5
HIGH 7.2
CVE-2020-15523 38490

Python 3.5.10, 3.6.12, 3.7.9, 3.8.4 and 3.9.0 include a fix for CVE-2…

  • <3.5.10
  • >=3.6.0a0,<3.6.12
  • >=3.7.0a0,<3.7.9
  • >=3.8.0a0,<3.8.4
  • >=3.9.0a0,<3.9.0
HIGH 7.8
PVE-2021-42386 45709

Python versions 3.9.0a6, 3.8.4, 3.7.8, 3.6.11, and 3.5.10 disallow CR…

  • <3.5.10
  • >=3.6.0a0,<3.6.11
  • >=3.7.0a0,<3.7.8
  • >=3.8.0a0,<3.8.4
  • >=3.9.0a0,<3.9.0a6
HIDDEN X.Y
CVE-2023-40217 60680

Python 3.8.18, 3.9.18, 3.10.13, 3.11.5 and 3.12.0rc2 include a fix fo…

  • >=3.12.0a1,<=3.12.0rc1
  • >=3.11.0a1,<3.11.5
  • >=3.10.0a1,<3.10.13
  • >=3.9.0a1,<3.9.18
  • <3.8.18
MEDIUM 5.3
CVE-2015-20107 48131

Python 3.7.16, 3.8.16, 3.9.16, 3.10.6 and 3.11.0b4 include a fix for …

  • >=3.11.0a0,<3.11.0b4
  • <3.7.16
  • >=3.8.0a0,<3.8.16
  • >=3.9.0a0,<3.9.16
  • >=3.10.0a0,<3.10.6
HIGH 7.6
CVE-2023-6597 66949

An issue was found in the CPython `tempfile.TemporaryDirectory` class…

  • >=3.10.0a1,<=3.10.13
  • >=3.9.0a1,<=3.9.18
  • >=0,<=3.8.18
  • >=3.12.0a1,<3.12.2
  • >=3.11.0a1,<3.11.8
- -
CVE-2024-0450 66951

An issue was found in the CPython `zipfile` module affecting versions…

  • >=3.10.0a1,<=3.10.13
  • >=3.9.0a1,<=3.9.18
  • >=0,<=3.8.18
  • >=3.12.0a1,<3.12.2
  • >=3.11.0a1,<3.11.8
- -
CVE-2023-24329 53376

Python 3.7.17, 3.8.17, 3.9.17, 3.10.12 and 3.11.4 include a fix for C…

  • >=3.10.0a0,<3.10.12
  • >=3.11.0a0,<3.11.4
  • >=3.9.0a0,<3.9.17
  • >=3.8.0a0,<3.8.17
  • <3.7.17
HIGH 7.5
CVE-2020-27619 45701

Python 3.6.13, 3.7.10, 3.8.7, 3.9.1 and 3.10.0a2 include a fix for CV…

  • >=3.0.0a0,<3.6.13
  • >=3.7.0a0,<3.7.10
  • >=3.8.0a0,<3.8.7
  • >=3.9.0a0,<3.9.1
  • >=3.10.0a0,<3.10.0a2
CRITICAL 9.8
CVE-2014-4616 45689

Python versions 2.7.7, 3.2.6, 3.3.6, 3.4.2 and 3.5.0 include a fix fo…

  • <2.7.7
  • >=3.0.0a0,<3.2.6
  • >=3.3.0a0,<3.3.6
  • >=3.4.0a0,<3.4.2
  • >=3.5.0a0,<3.5.0
MEDIUM 5.9
CVE-2014-1912 45688

Python versions 2.7.7, 3.1.5, 3.2.6, 3.3.4 and 3.4.0 include a fix fo…

  • <2.7.7
  • >=3.0.0a0,<3.1.5
  • >=3.2.0a0,<3.2.6
  • >=3.3.0a0,<3.3.4
  • >=3.4.0a0,<3.4.0
HIGH 7.5
CVE-2019-18348 45647

Python 2.7.18rc1, 3.5.10rc1, 3.6.11rc1, 3.7.8rc1 and 3.8.3rc1 include…

  • <2.7.18rc1
  • >=3.0.0a0,<3.5.10rc1
  • >=3.6.0a0,<3.6.11rc1
  • >=3.7.0a0,<3.7.8rc1
  • >=3.8.0a0,<3.8.3rc1
MEDIUM 6.1
CVE-2019-12900 70532

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-b…

  • <2.7.18rc1
  • >=3.0.0a0,<3.5.10rc1
  • >=3.6.0a0,<3.6.11rc1
  • >=3.7.0a0,<3.7.8rc1
  • >=3.8.0a0,<3.8.3rc1
CRITICAL 9.8
CVE-2019-10160 45708

Python versions 3.8.0b2, 3.7.4, 3.6.10, 3.5.8 and 2.7.17 include a fi…

  • <2.7.17
  • >=3.0.0a0,<3.5.8
  • >=3.6.0a0,<3.6.10
  • >=3.7.0a0,<3.7.4
  • >=3.8.0a0,<3.8.0b2
CRITICAL 9.8
CVE-2019-5010 45680

Python versions 2.7.16, 3.4.10, 3.5.7, 3.6.9 and 3.7.3 include a fix …

  • <2.7.16
  • >=3.0.0a0,<3.4.10
  • >=3.5.0a0,<3.5.7
  • >=3.6.0a0,<3.6.9
  • >=3.7.0a0,<3.7.3
HIGH 7.5
CVE-2018-20852 45679

Python versions 2.7.16, 3.4.10, 3.5.7, 3.6.9 and 3.7.3 include a fix …

  • <2.7.16
  • >=3.0.0a0,<3.4.10
  • >=3.5.0a0,<3.5.7
  • >=3.6.0a0,<3.6.9
  • >=3.7.0a0,<3.7.3
MEDIUM 5.3
CVE-2018-14647 45677

Python versions 2.7.16, 3.4.10, 3.5.7, 3.6.7 and 3.7.1 include a fix …

  • <2.7.16
  • >=3.0.0a0,<3.4.10
  • >=3.5.0a0,<3.5.7
  • >=3.6.0a0,<3.6.7
  • >=3.7.0a0,<3.7.1
HIGH 7.5
CVE-2018-1060 45654

Python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is…

  • <2.7.15
  • >=3.0.0a0,<3.4.9
  • >=3.5.0a0,<3.5.6rc1
  • >=3.6.0a0,<3.6.5rc1
  • >=3.7.0a0,<3.7.0
HIGH 7.5
CVE-2018-1061 45653

Python before versions 2.7.15, 3.4.9, 3.5.6, 3.6.5 and 3.7.0 is vulne…

  • <2.7.15
  • >=3.0.0a0,<3.4.9
  • >=3.5.0a0,<3.5.6
  • >=3.6.0a0,<3.6.5
  • >=3.7.0a0,<3.7.0
HIGH 7.5
PVE-2021-42403 45671

Python versions 2.7.14, 3.3.7, 3.4.7, 3.5.4 and 3.6.3 fix ftplib.FTP.…

  • <2.7.14
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
  • >=3.6.0a0,<3.6.3
- -
CVE-2016-4472 45668

Python versions 2.7.14, 3.3.7, 3.4.7, 3.5.4 and 3.6.2 update modules/…

  • <2.7.14
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
  • >=3.6.0a0,<3.6.2
HIGH 8.1
CVE-2016-5300 45669

Python versions 2.7.14, 3.3.7, 3.4.7, 3.5.4 and 3.6.2 update modules/…

  • <2.7.14
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
  • >=3.6.0a0,<3.6.2
HIGH 7.5
CVE-2012-6702 45670

Python versions 2.7.14, 3.3.7, 3.4.7, 3.5.4 and 3.6.2 update modules/…

  • <2.7.14
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
  • >=3.6.0a0,<3.6.2
MEDIUM 5.9
CVE-2016-0718 45667

Python versions 2.7.14, 3.3.7, 3.4.7, 3.5.4 and 3.6.2 update modules/…

  • <2.7.14
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
  • >=3.6.0a0,<3.6.2
CRITICAL 9.8
CVE-2017-9233 70736

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expa…

  • >=2.7.0,<2.7.15
  • >=3.3.0,<3.3.7
  • >=3.4.0,<3.4.7
  • >=3.5.0,<3.5.4
  • >=3.6.0,<3.6.2
HIGH 7.5
CVE-2013-4238 45663

Python versions 2.6.9, 2.7.7, 3.2.6, 3.3.6 and 3.4.1 include a fix fo…

  • <2.6.9
  • >=2.7.0a0,<2.7.7
  • >=3.2.0a0,<3.2.6
  • >=3.3.0a0,<3.3.6
  • >=3.4.0a0,<3.4.1
MEDIUM 4.3
CVE-2011-4940 45718

Python 2.5.6c1, 2.6.7rc2, 2.7.2, 3.2.4 and 3.3.1 include a fix for CV…

  • >=2.6,<2.6.7
  • <2.5.6c1
  • >=2.7,<2.7.2
  • >=3.0.0a0,<3.2.4
  • >=3.3.0a0,<3.3.1
LOW 2.6
CVE-2022-37454 51647

Python 3.7.16, 3.8.16, 3.9.16 and 3.10.9 include a fix for CVE-2022-3…

  • <3.7.16
  • >=3.8.0a0,<3.8.16
  • >=3.9.0a0,<3.9.16
  • >=3.10.0a0,<3.10.9
CRITICAL 9.8
CVE-2022-40674 51863

Python 3.7.15, 3.8.15, 3.9.15 and 3.10.8 update bundled 'libexpat' ve…

  • <3.7.15
  • >=3.8.0a0,<3.8.15
  • >=3.9.0a0,<3.9.15
  • >=3.10.0a0,<3.10.8
HIGH 8.1
CVE-2021-28861 50732

Python 3.7.14, 3.8.14, 3.9.14 and 3.10.6 include a fix for CVE-2021-2…

  • <3.7.14
  • >=3.8.0a0,<3.8.14
  • >=3.9.0a0,<3.9.14
  • >=3.10.0a0,<3.10.6
HIGH 7.4
CVE-2022-22827 51867

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 8.8
CVE-2022-25236 51864

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-22825 51869

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 8.8
CVE-2022-22822 51872

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-25315 51861

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-26488 45817

In Python before 3.10.3 on Windows, local users can gain privileges b…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 7.0
CVE-2022-23990 51865

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 7.5
CVE-2022-25235 51862

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-23852 51866

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-25314 51860

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 7.5
CVE-2021-45960 51874

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 8.8
CVE-2021-46143 51873

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 7.8
CVE-2022-22823 51871

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-22824 51870

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
CRITICAL 9.8
CVE-2022-25313 51858

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
MEDIUM 6.5
CVE-2022-22826 51868

Python 3.7.13, 3.8.13, 3.9.11 and 3.10.3 update bundled libexpat vers…

  • <3.7.13
  • >=3.8.0a0,<3.8.13
  • >=3.9.0a0,<3.9.11
  • >=3.10.0a0,<3.10.3
HIGH 8.8
CVE-2021-23336 45719

Python versions 3.6.13, 3.7.10, 3.8.8 and 3.9.2 include a fix for CVE…

  • >=3.7.0,<3.7.10
  • >=3.8.0,<3.8.8
  • >=3.9.0,<3.9.2
  • <3.6.13
MEDIUM 5.9
CVE-2021-3177 45651

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _cty…

  • >=3.7.0,<3.7.10
  • >=3.8.0,<3.8.8
  • >=3.9.0,<3.9.2
  • >=3.0.0a0,<3.6.13
CRITICAL 9.8
CVE-2018-1000117 70750

Python Software Foundation CPython version From 3.2 until 3.6.4 on Wi…

  • ==3.7.0
  • >=3.2.0,<3.4.9
  • >=3.5.0,<3.5.6
  • >=3.6.0,<3.6.5
MEDIUM 6.7
CVE-2021-4189 50765

Python 3.6.14, 3.7.11, 3.8.9 and 3.9.3 include a fix for CVE-2021-418…

  • <3.6.14
  • >=3.7.0a0,<3.7.11
  • >=3.8.0a0,<3.8.9
  • >=3.9.0a0,<3.9.3
MEDIUM 5.3
CVE-2022-48560 60628

Python 3.6.11, 3.7.7 and 3.8.2 include a fix for CVE-2022-48560: Use …

  • <3.6.11
  • >=3.7.0a1,<3.7.7
  • >=3.8.0a1,<3.8.2
  • >=3.9.0a1,<3.9.0a3
HIGH 7.5
CVE-2013-0340 70601

expat 2.1.0 and earlier does not properly handle entities expansion u…

  • >=3.6.0,<3.6.15
  • >=3.7.0,<3.7.12
  • >=3.8.0,<3.8.12
  • >=3.9.0,<3.9.7
MEDIUM 6.8
CVE-2019-20907 45650

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to cra…

  • <3.5.10
  • >=3.6.0a0,<3.6.15
  • >=3.7.0a0,<3.7.9
  • >=3.8.0a0,<3.8.4
HIGH 7.5
CVE-2014-2667 45694

Python versions 3.2.5, 3.3.6, 3.4.2 and 3.5.0 include a fix for CVE-2…

  • >=3.2.0a0,<3.2.5
  • >=3.3.0a0,<3.3.6
  • >=3.4.0a0,<3.4.2
  • >=3.5.0a0,<3.5.0
LOW 3.3
CVE-2024-0397 71775

A defect was discovered in the Python “ssl” module where there is a m…

  • <3.10.14
  • >=3.11.0a0,<3.11.9
  • >=3.12.0a0,<3.12.3
  • >=3.13.0a0,<3.13.0a5
- -
CVE-2016-3189 70617

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows re…

  • >=3.10.0,<3.10.3
  • >=3.7.0,<3.7.13
  • >=3.8.0,<3.8.13
  • >=3.9.0,<3.9.11
MEDIUM 6.5
CVE-2019-16056 45683

Python versions 2.7.17, 3.5.8, 3.6.10 and 3.7.5 include a fix for CVE…

  • >=3.0.0a0,<3.5.8
  • >=3.6.0a0,<3.6.10
  • >=3.7.0a0,<3.7.5
  • <2.7.17
HIGH 7.5
CVE-2018-20406 45695

Python versions 3.4.10, 3.5.7, 3.6.7 and 3.7.1 include a fix for CVE-…

  • >=3.0.0a0,<3.4.10
  • >=3.5.0a0,<3.5.7
  • >=3.6.0a0,<3.6.7
  • >=3.7.0a0,<3.7.1
HIGH 7.5
CVE-2013-1753 45692

Python versions 2.7.9, 3.2.6, 3.3.6 and 3.4.3 include a fix for CVE-2…

  • <2.7.9
  • >=3.2.0a0,<3.2.6
  • >=3.3.0a0,<3.3.6
  • >=3.4.0a0,<3.4.3
HIGH 7.5
CVE-2013-1752 45676

Python versions 2.7.9, 3.2.6, 3.3.7 and 3.4.3 include a fix for CVE-2…

  • <2.7.9
  • >=3.0.0a0,<3.2.6
  • >=3.3.0a0,<3.3.7
  • >=3.4.0a0,<3.4.3
MEDIUM 4.3
CVE-2014-4650 45690

Python versions 2.7.8, 3.2.6, 3.3.6 and 3.4.2 include a fix for CVE-2…

  • <2.7.8
  • >=3.0.0a0,<3.2.6
  • >=3.3.0a0,<3.3.6
  • >=3.4.0a0,<3.4.2
CRITICAL 9.8
CVE-2012-0845 45710

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2…

  • >=2.7,<2.7.3
  • >=3.2,<3.2.3
  • >=3.1,<3.1.5
  • <2.6.8
MEDIUM 5.0
CVE-2012-1150 45652

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x …

  • >=2.7,<2.7.3
  • >=3.0,<3.1.5
  • >=3.2,<3.2.3
  • <2.6.8
MEDIUM 5.0
CVE-2019-9947 45686

Python versions 2.7.17, 3.5.8, 3.6.9 and 3.7.4 include a fix for CVE-…

  • <2.7.17
  • >=3.0.0a0,<3.5.8
  • >=3.6.0a0,<3.6.9
  • >=3.7.0a0,<3.7.4
MEDIUM 6.1
CVE-2019-9740 45685

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and u…

  • <2.7.17
  • >=3.0.0a0,<3.5.8
  • >=3.6.0a0,<3.6.9
  • >=3.7.0a0,<3.7.4
MEDIUM 6.1
CVE-2019-9948 45684

Python versions 2.7.17, 3.5.8, 3.6.10 and 3.7.5 include a fix for CVE…

  • <2.7.17
  • >=3.0.0a0,<3.5.8
  • >=3.6.0a0,<3.6.10
  • >=3.7.0a0,<3.7.5
CRITICAL 9.1
CVE-2019-9636 45682

Python versions 2.7.17, 3.5.7, 3.6.9 and 3.7.3 include a fix for CVE-…

  • <2.7.17
  • >=3.0.0a0,<3.5.7
  • >=3.6.0a0,<3.6.9
  • >=3.7.0a0,<3.7.3
CRITICAL 9.8
CVE-2019-16935 45681

Python versions 2.7.17, 3.5.10, 3.6.10 and 3.7.5 include a fix for CV…

  • <2.7.17
  • >=3.0.0a0,<3.5.10
  • >=3.6.0a0,<3.6.10
  • >=3.7.0a0,<3.7.5
MEDIUM 6.1
CVE-2016-1000110 45666

Python versions 2.7.13, 3.3.7, 3.4.6 and 3.5.3 include a fix for CVE-…

  • <2.7.13
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.6
  • >=3.5.0a0,<3.5.3
MEDIUM 6.1
PVE-2021-42408 45665

Python versions 2.7.13, 3.3.7, 3.4.6 and 3.5.3 fix an arbitrary code …

  • <2.7.13
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.6
  • >=3.5.0a0,<3.5.3
HIDDEN X.Y
CVE-2015-1283 70615

Multiple integer overflows in the XML_GetBuffer function in Expat thr…

  • >=2.7.0,<2.7.12
  • >=3.3.0,<3.3.7
  • >=3.4.0,<3.4.5
  • >=3.5.0,<3.5.2
MEDIUM 6.8
CVE-2010-3493 45655

Python version 2.6.7, 2.7.2, 3.1.4 and 3.2.0 include a fix for CVE-20…

  • <2.6.7
  • >=2.7.0a0,<2.7.2
  • >=3.0.0a0,<3.1.4
  • >=3.2.0a0,<3.2.0
MEDIUM 4.3
CVE-2010-2089 45662

Python versions 2.6.6, 2.7.0, 3.1.3 and 3.2.0 include a fix for CVE-2…

  • <2.6.6
  • >=2.7.0a0,<2.7.0
  • >=3.0.0a0,<3.1.3
  • >=3.2.0a0,<3.2.0
MEDIUM 5.0
CVE-2010-1634 45661

Python versions 2.6.6, 2.7.0, 3.1.3 and 3.2.0 include a fix for CVE-2…

  • <2.6.6
  • >=2.7.0a0,<2.7.0
  • >=3.0.0a0,<3.1.3
  • >=3.2.0a0,<3.2.0
MEDIUM 5.0
CVE-2012-0876 70616

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash value…

  • >=2.6.0,<2.6.8
  • >=2.7.0,<2.7.3
  • >=3.1.0,<3.1.5
  • >=3.2.0,<3.2.3
MEDIUM 4.3
CVE-2022-42919 51714

Python 3.9.16, 3.10.9 and 3.11.0 include a fix for CVE-2022-42919: Py…

  • <3.9.16
  • >=3.10.0a0,<3.10.9
  • >=3.11.0a0,<3.11.0
HIGH 7.8
PVE-2021-42387 45700

Python versions 3.6.10, 3.7.6 and 3.8.1 fix loop.create_datagram_endp…

  • <3.6.10
  • >=3.7.0a0,<3.7.6
  • >=3.8.0a0,<3.8.1
- -
PVE-2021-42390 45699

Python versions 3.6.10, 3.7.5 and 3.8.0 fix an infinite loop with sho…

  • <3.6.10
  • >=3.7.0a0,<3.7.5
  • >=3.8.0a0,<3.8.0
- -
CVE-2020-8315 70586

In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 th…

  • >=3.6.0,<=3.6.10
  • >=3.7.0,<=3.7.6
  • >=3.8.0,<=3.8.1
MEDIUM 5.5
CVE-2021-29921 45614

Python 3.8.12, 3.9.5 and 3.10.0 include a fix for CVE-2021-29921: In …

  • >=3.10.0a0,<3.10.0
  • >=3.9.0a0,<3.9.5
  • >=3.8.0a0,<3.8.12
CRITICAL 9.8
CVE-2017-1000158 45675

Python versions 2.7.14, 3.4.8 and 3.5.5 include a fix for CVE-2017-10…

  • <2.7.14
  • >=3.5.0a0,<3.5.5
  • >=3.0.0a0,<3.4.8
CRITICAL 9.8
CVE-2016-9841 45673

Python versions 2.7.14, 3.4.7 and 3.5.4 update its dependency 'zlib' …

  • <2.7.14
  • >=3.0.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
CRITICAL 9.8
CVE-2016-9840 45672

Python versions 2.7.14, 3.4.7 and 3.5.4 update its dependency 'zlib' …

  • <2.7.14
  • >=3.0.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
HIGH 8.8
CVE-2016-9842 45674

Python versions 2.7.14, 3.4.7 and 3.5.4 update its dependency 'zlib' …

  • <2.7.14
  • >=3.0.0a0,<3.4.7
  • >=3.5.0a0,<3.5.4
HIGH 8.8
CVE-2016-0772 45720

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before…

  • <2.7.12
  • >=3.0,<3.4.5
  • >=3.5,<3.5.2
MEDIUM 6.5
CVE-2016-5636 45617

Integer overflow in the get_data function in zipimport.c in CPython (…

  • <2.7.12
  • >=3.0,<3.4.5
  • >=3.5,<3.5.2
CRITICAL 9.8
CVE-2016-5699 45664

Python versions 2.7.10, 3.3.7 and 3.4.4 include a fix for CVE-2016-56…

  • <2.7.10
  • >=3.0.0a0,<3.3.7
  • >=3.4.0a0,<3.4.4
MEDIUM 6.1
CVE-2011-1015 45660

Python versions 2.5.5, 2.6.4 and 3.1 include a fix for CVE-2011-1015:…

  • <2.5.5
  • >=2.6.0a0,<2.6.4
  • >=3.0.0a0,<3.1
MEDIUM 5.0
PVE-2021-42391 45707

Python versions 3.7.4 and 3.8.0 includes a fix for ssl.match_hostname…

  • >=3.8.0a0,<3.8.0
  • >=3.7.0a0,<3.7.4
- -
CVE-2020-15801 70751

In Python 3.8.4, sys.path restrictions specified in a python38._pth f…

  • >=3.7.0,<3.7.9
  • >=3.8.0,<3.8.5
CRITICAL 9.8
PVE-2021-42398 45706

Python versions 3.6.7 and 3.7.1 disable external entities in SAX pars…

  • <3.6.7
  • >=3.7.0a0,<3.7.1
- -
CVE-2016-2183 45716

Python 3.4.7 and 3.5.3 remove 3DES from SSL default ciphers list, as …

  • >=3.5.0a0,<3.5.3
  • <3.4.7
HIGH 7.5
CVE-2013-2099 45693

Algorithmic complexity vulnerability in the ssl.match_hostname functi…

  • >=3.3.0a0,<3.3.3
  • <3.2.6
MEDIUM 4.3
CVE-2023-27043 55080

The e-mail module of Python 0 - 2.7.18, 3.x - 3.11 incorrectly parses…

  • >3.0,<3.11.3
  • <2.7.18
MEDIUM 5.3
CVE-2014-9365 45691

Python versions 2.7.9 and 3.4.3 include a fix for CVE-2014-9365: The …

  • <2.7.9
  • >=3.0.0a0,<3.4.3
MEDIUM 5.8
CVE-2013-7440 45656

Python version 2.7.9 and 3.3.3 include a fix for CVE-2013-7440: The s…

  • <2.7.9
  • >=3.0.0a0,<3.3.3
MEDIUM 5.9
CVE-2010-3492 45687

Python versions 2.7.3 and 3.1.5 include a fix for CVE-2010-3492: The …

  • <2.7.3
  • >=3.0.0a0,<3.1.5
MEDIUM 5.0
CVE-2011-1521 45721

The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x bef…

  • <2.7.2
  • >=3.0.0a0,<3.2.1
MEDIUM 6.4
CVE-2019-13404 70573

The MSI installer for Python through 2.7.16 on Windows defaults to th…

  • <=2.7.16
  • >=3.0.0,<3.5.0
HIGH 7.8
CVE-2014-0224 70622

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h …

  • >=2.7.0,<2.7.8
  • >=3.4.0,<3.4.2
HIGH 7.4
CVE-2008-5983 61224

Untrusted search path vulnerability in the PySys_SetArgv API function…

  • <=2.6.6
  • >=3.1.0,<3.1.3
MEDIUM 6.9
CVE-2011-4944 45644

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissi…

  • >=2.6.0a0,<2.7.3
  • >=3.0.0a0,<3.3
LOW 1.9
CVE-2008-5031 45659

Python versions 2.4.6 and 2.5.2 include a fix for CVE-2008-5031: Mult…

  • <2.4.6
  • >=2.5.0a0,<2.5.2
HIGH 10.0
CVE-2005-0089 61218

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5…

  • >=2.2,<2.3.5
  • >2.3.5,<=2.4
HIGH 7.5
PVE-2021-42393 45612

In difflib module, table header in output of difflib.HtmlDiff.make_ta…

  • <3.8
HIDDEN X.Y
CVE-2019-9674 45621

Lib/zipfile.py in Python allows remote attackers to cause a denial of…

  • <3.7.2
HIGH 7.5
CVE-2018-8970 45658

Python version 3.7.0b3 hardens ssl module against CVE-2018-8970. htt…

  • >=3.7.0a0,<3.7.0b3
HIGH 7.4
CVE-2016-9063 70521

An integer overflow during the parsing of XML using the Expat library…

  • <3.6.2
CRITICAL 9.8
CVE-2015-5652 70413

Untrusted search path vulnerability in python.exe in Python through 3…

  • <=3.5.0
HIGH 7.2
CVE-2013-7040 45657

Python version 3.4 includes a fix for CVE-2013-7040: Python before 3.…

  • <3.4.0
MEDIUM 4.3
CVE-2012-2135 45722

The utf-16 decoder in Python 3.1 through 3.3 does not update the alig…

  • >=3.1,<3.4
MEDIUM 6.4
CVE-2023-6507 70382

An issue was found in CPython 3.12.0 `subprocess` module on POSIX pla…

  • <3.12.1
MEDIUM 4.9
CVE-2023-33595 58960

Python 3.12.0a7, as downloaded from Github repository after commit 13…

  • ==3.12.0a7
MEDIUM 5.5
CVE-2023-41105 60640

An issue was discovered in Python 3.11 through 3.11.4. If a path cont…

  • >=3.11.0a1,<3.11.4
HIGH 7.5
CVE-2013-7338 45649

Python 3.3.4rc1 includes a fix for CVE-2013-7338: Python before 3.3.4…

  • >=3.0.0a0,<3.3.4rc1
HIGH 7.1
CVE-2014-7185 45648

Python 2.7.8 includes a fix for CVE-2014-7185: Integer overflow in bu…

  • <2.7.8
MEDIUM 6.4
CVE-2018-1000802 45646

Python 2.7.16 includes a fix for CVE-2018-1000802: Python Software Fo…

  • <2.7.16
CRITICAL 9.8
CVE-2018-1000030 45645

Python 2.7.15 includes a fix for CVE-2018-1000030: Python 2.7.14 is v…

  • <2.7.15
LOW 3.6
CVE-2006-4980 54917

Buffer overflow in the repr function in Python 2.3 through 2.6 before…

  • <2.6.6
HIGH 7.5
CVE-2010-1450 45624

Multiple buffer overflows in the RLE decoder in the rgbimg module in …

  • <2.6
HIGH 7.5
CVE-2009-4134 45605

Buffer underflow in the rgbimg module in Python 2.5 allows remote att…

  • <2.6
MEDIUM 5.0
CVE-2010-1449 45616

Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5…

  • <2.6
HIGH 7.5
CVE-2008-1679 45625

Multiple integer overflows in imageop.c in Python before 2.5.3 allow …

  • <2.5.3
MEDIUM 6.8
CVE-2008-1721 45618

Integer signedness error in the zlib extension module in Python 2.5.2…

  • <2.5.2
HIGH 7.5
CVE-2008-1887 45643

Python 2.5.2 and earlier allows context-dependent attackers to execut…

  • <2.5.2
HIGH 9.3
CVE-2008-2315 61294

Multiple integer overflows in Python 2.5.2 and earlier allow context-…

  • <=2.5.2
HIGH 7.5
CVE-2008-3144 61292

Multiple integer overflows in the PyOS_vsnprintf function in Python/m…

  • <=2.5.2
MEDIUM 5.0
CVE-2008-3143 61293

Multiple integer overflows in Python before 2.5.2 might allow context…

  • <=2.5.2
HIGH 7.5
CVE-2008-3142 61290

Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platfo…

  • <=2.5.2
HIGH 7.5
CVE-2007-1657 61222

Stack-based buffer overflow in the file_compress function in minigzip…

  • ==2.5
HIGH 7.5
CVE-2007-2052 61295

Off-by-one error in the PyLocale_strxfrm function in Modules/_localem…

  • >=2.4,<=2.5
MEDIUM 5.0
CVE-2006-1542 61220

Stack-based buffer overflow in Python 2.4.2 and earlier, running on L…

  • >=2.4,<=2.4.2
LOW 3.7
CVE-2019-15903 70596

In libexpat before 2.2.8, crafted XML input could fool the parser int…

  • <2.2.8
HIGH 7.5
CVE-2004-0150 61219

Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.…

  • >=2.2,<=2.2.1
HIGH 7.5
CVE-2002-1119 61221

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary …

  • <=2.2.1
MEDIUM 4.6
CVE-2017-20052 49455

A vulnerability classified as problematic was found in Python 2.7.13.…

  • <2.17.14
HIGH 7.8
CVE-2023-0593 63025

This is a dummy vulnerability only.

  • >201.1.1
MEDIUM 5.5
CVE-2008-4864 61291

Multiple integer overflows in imageop.c in the imageop module in Pyth…

  • >=1.5.2,<2.5.3
HIGH 7.5
CVE-2008-2316 61223

Integer overflow in _hashopenssl.c in the hashlib module in Python 2.…

  • >=1.5.2,<=2.5.2
HIGH 7.5
CVE-2007-4965 61261

Multiple integer overflows in the imageop module in Python 2.5.1 and …

  • >=1.5.2,<=2.5.1
MEDIUM 5.8