Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2020-29651

Medium priority

Some fixes available 2 of 4

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame...

1 affected package

python-py

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-py Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-5390

Medium priority
Fixed

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object...

1 affected package

python-pysaml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Fixed
Show less packages

CVE-2018-1000872

Medium priority
Needs evaluation

OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or...

1 affected package

python-pykmip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pykmip Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-1000433

Medium priority
Fixed

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

1 affected package

python-pysaml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2
Show less packages

CVE-2017-1000246

Negligible priority
Vulnerable

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

1 affected package

python-pysaml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10149

Medium priority

Some fixes available 2 of 3

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

1 affected package

python-pysaml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2
Show less packages

CVE-2016-10127

Low priority
Ignored

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

1 affected package

python-pysaml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pysaml2 Not affected
Show less packages

CVE-2014-4615

Medium priority

Some fixes available 3 of 4

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated...

3 affected packages

ceilometer, neutron, python-pycadf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceilometer
neutron
python-pycadf
Show less packages

CVE-2010-3494

Medium priority
Needs evaluation

Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the...

1 affected package

python-pyftpdlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pyftpdlib Not affected Not affected Needs evaluation Needs evaluation
Show less packages