Search CVE reports
1 – 10 of 25 results
pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected...
1 affected package
python-pyzipper
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-pyzipper | Needs evaluation | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer....
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode....
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code...
1 affected package
python-pyvista
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-pyvista | Needs evaluation | Not in release | Not in release | — | — |
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by...
1 affected package
python-pythonjsonlogger
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-pythonjsonlogger | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
Some fixes available 8 of 10
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
1 affected package
python-pymysql
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-pymysql | Fixed | Fixed | Fixed | Fixed | Needs evaluation |
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a...
1 affected package
python-pyramid
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-pyramid | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |