Python 3.0

cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*

Vendor: Python · Product: Python · Version: 3.0

13
Total CVEs
More Total CVEs than 91% of tracked CPEs
2.6
Avg CVEs / Year
More Avg CVEs / Year than 78% of tracked CPEs
5.7
Avg CVSS
Higher Avg CVSS Score than 28% of tracked CPEs
0.0%
KEV Rate
Bottom 1%

CVE Activity Over Time

CVE Activity By Year

Signals from CVEs in this cpe scope (13 CVEs).

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2011
15 years ago
Most Recent CVE
Sep 2, 2016
3,616 days ago

Exploit Intelligence

Signals from CVEs in this cpe scope (13 CVEs).

CISA KEV
NO0 CVEs
Metasploit
NO0 CVEs
Nuclei
NO0 CVEs
ExploitDB
YES2 CVEs

Social Chatter

Signals from CVEs in this cpe scope (13 CVEs).

Media Mentions

Signals from CVEs in this cpe scope (13 CVEs).

Top CVEs

Signals from CVEs in this cpe scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to exec
Mar 1, 20147.539NOYES
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified
Sep 2, 20169.834NONO
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middl
Sep 2, 20166.532NOYES
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to in
Sep 2, 20166.124NONO
The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote att
May 24, 20116.424NONO
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attac
Jun 7, 20165.922NONO
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL
Dec 12, 20145.822NONO
Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which
Oct 5, 20125.021NONO
SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of servic
Oct 5, 20125.021NONO
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash c
May 19, 20144.319NONO

Version CVEs

CVE IDPublishedFAUCET ScoreCVSSEPSSKEV
Jul 9, 202638.07.50.6%NO
Jun 30, 202628.05.30.3%NO
Jun 8, 202635.08.20.4%NO
Jun 4, 202630.06.90.6%NO
Jun 3, 202629.06.30.5%NO
May 13, 202630.05.90.5%NO
May 11, 202634.07.50.8%NO
Apr 27, 202625.07.50.5%NO
Apr 22, 202626.06.10.2%NO
Apr 13, 202631.07.10.3%NO
Apr 13, 202634.08.10.6%NO
Apr 10, 202623.06.00.2%NO
Apr 10, 202627.05.70.6%NO
Mar 20, 202622.03.30.3%NO
Mar 18, 202612.00.00.2%NO
Mar 16, 202628.07.50.6%NO
Mar 16, 202630.07.50.4%NO
Mar 12, 202617.03.30.2%NO
Mar 4, 202623.05.70.2%NO
Jan 23, 202624.06.00.6%NO
Jan 21, 202620.05.30.5%NO
Jan 20, 202625.05.90.5%NO
Jan 20, 202625.06.00.4%NO
Jan 20, 202625.06.00.5%NO
Jan 20, 202624.05.70.5%NO