VAITP Dataset

Dataset Statistics
Search for CVE
#
CVE
Vulnerability
ODC
Category
Subcategory
Accessibility Scope
Details
Total vulnerabilities in the dataset (not showing ignored and non-python related vulnerabilties): 1612
735
CVE-2019-3558
Python Facebook Thrift servers < v2019.02.18.00: Parsing DoS via unknown type containers

Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

Timing/Serialization
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
734
CVE-2022-25882
onnx < 1.13.0: Directory Traversal in external_data field

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

Function
Input Validation and Sanitization
Path Traversal
Local
733
CVE-2013-1629
Insecure package retrieval in pre-1.3 pip allows code execution via crafted response

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Function
Cryptographic
Unencrypted communication
Remote
732
CVE-2018-0015
AppFormix debug console allows root command execution

A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. If the host is executing AppFormix Agent, an attacker may access the debug console and execute Python commands with root privilege. Affected AppFormix releases are: All versions up to and including 2.7.3; 2.11 versions prior to 2.11.3; 2.15 versions prior to 2.15.2. Juniper SIRT is not aware of any malicious exploitation of this vulnerability, however, the issue has been seen in a production network. No other Juniper Networks products or platforms are affected by this issue.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Remote
731
CVE-2019-9852
LibreOffice : Macro Execution Bypass

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed. However this new protection could be bypassed by a URL encoding attack. In the fixed versions, the parsed url describing the script location is correctly encoded before further processing. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

Function
Input Validation and Sanitization
Path Traversal
Remote
730
CVE-2022-41607
ETIC RAS 4.5.0 and earlier API directory traversal vulnerability

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and priorโ€™s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more.

Function
Input Validation and Sanitization
Path Traversal
Remote
729
CVE-2022-30034
Flower (Celery web UI) OAuth bypass vulnerability

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

Function
Authentication, Authorization, and Session Management
Insecure Authentication Mechanisms
Remote
728
CVE-2021-33571
Django 2.2 < 2.2.24, 3.x < 3.1.12, 3.2 < 3.2.4: IP validation allows leading zero in octal literals

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
727
CVE-2021-28667
StackStorm < 3.4.1, Python 3.x, non-utf-8 locale, Unicode data, infinite loop

StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name).

Function
Resource Management
Resource Exhaustion
Local
726
CVE-2018-6461
Insecure Library Loading in March Hare WINCVS before 2.8.01 and CVS Suite before 2009R2 build 6610 via DLL files

March Hare WINCVS before 2.8.01 build 6610, and CVS Suite before 2009R2 build 6610, contains an Insecure Library Loading vulnerability in the wincvs2.exe or wincvs.exe file, which may allow local users to gain privileges via a Trojan horse Python or TCL DLL file in the current working directory.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Local
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::