Search CVE reports


Toggle filters

241 – 250 of 829 results


CVE-2024-40647

Medium priority
Needs evaluation

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses despite the `env={}` setting. In Python's `subprocess` calls, all environment...

1 affected package

sentry-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sentry-python Needs evaluation Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2024-21170

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network...

1 affected package

mysql-connector-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-python Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-6345

Medium priority
Fixed

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or...

3 affected packages

python-pip, python-setuptools, setuptools

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Not affected Not affected Not affected Fixed Fixed
python-setuptools Not in release Not in release Fixed Fixed Fixed
setuptools Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-39614

Medium priority

Some fixes available 5 of 7

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-39330

Low priority

Some fixes available 5 of 7

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations...

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-39329

Low priority

Some fixes available 5 of 7

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests...

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-38875

Medium priority

Some fixes available 5 of 7

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-5569

Medium priority

Some fixes available 3 of 4

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This...

1 affected package

python-zipp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-zipp Fixed Fixed Fixed
Show less packages

CVE-2024-39689

Negligible priority
Ignored

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized...

2 affected packages

python-certifi, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-certifi Not affected Not affected Not affected Not affected
python-pip Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-5642

Low priority
Vulnerable

CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see...

10 affected packages

python2.7, python3.10, python3.11, python3.12, python3.4...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python2.7 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
python3.10 Not in release Not in release Not affected Not in release
python3.11 Not in release Not in release Not affected Not in release
python3.12 Not in release Not affected Not in release Not in release
python3.4 Not in release Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Not in release Not affected
python3.7 Not in release Not in release Not in release Not in release Not affected
python3.8 Not in release Not in release Not in release Not affected Not affected
python3.9 Not in release Not in release Not in release Needs evaluation
Show all 10 packages Show less packages