Logilab maintains a specialized utility library—logilab-common—that provides common functions for Python applications, with a narrow but upstream-positioned vulnerability footprint. Observed disclosures center on link-following and file-access handling issues, which reflect risks typical of utility code that processes filesystem operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logilab over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-1839MEDIUM The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file. | Mar 11, 2014 | 4.4 | 14 | NO | NO |
CVE-2014-1838MEDIUM The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unsp | Mar 11, 2014 | 4.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logilab.
Media articles that mention a CVE ID that affects a product developed by Logilab — matched by CVE ID, not by vendor name.