VYPR

Bitnami package

python

pkg:bitnami/python

Vulnerabilities (105)

  • CVE-2020-15523HigJul 4, 2020
    affected >= 3.5.0, < 3.5.10fixed 3.5.10

    In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for pyth

  • CVE-2020-14422MedJun 18, 2020
    affected >= 3.0.0, < 3.5.10fixed 3.5.10

    Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or I

  • CVE-2020-8492MedJan 30, 2020
    affected >= 2.7.0, < 2.7.18fixed 2.7.18

    Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtr

  • CVE-2020-8315MedJan 28, 2020
    affected >= 3.6.0, < 3.6.11fixed 3.6.11

    In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are u

  • CVE-2007-4559CriAug 28, 2007
    affected < 3.6.16fixed 3.6.16

    Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

Page 6 of 6