VAITP Dataset

Dataset Statistics
Search for CVE
#
CVE
Vulnerability
ODC
Category
Subcategory
Accessibility Scope
Details
Total vulnerabilities in the dataset (not showing ignored and non-python related vulnerabilties): 1612
674
CVE-2017-12301
Cisco NX-OS: Local attacker escapes Python sandbox, gains unauthorized device OS access

A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Local
673
CVE-2022-30298
Privilege vuln in FortiSOAR < 7.2.1 lets GUI user run root Python commands via file modification

An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Local
672
CVE-2012-3533
oVirt 3.1: Python SDK < 3.1.0.6 and CLI < 3.1.0.8 skip SSL certificate verification, allowing MITM attacks

The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack.

Checking
Cryptographic
Improper SSL/TLS Certificate Validation
Remote
671
CVE-2023-26112
configobj package: Vulnerable to ReDoS in validate function with the pattern (.+?)(.โˆ—)(.โˆ—)

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\).

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
670
CVE-2023-0297
Code injection vulnerability in pyload/pyload < 0.5.0b3.dev31

Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

Function
Input Validation and Sanitization
Command Injection
Remote
669
CVE-2021-23418
XXE Injection in glances < 3.2.1 via Fault in XML parsing

The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
668
CVE-2022-0718
Python-oslo-utils exposes plaintext passwords in debug logs when they contain a double quote

A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
667
CVE-2015-4234
Cisco NX-OS local root access via Python interpreter (CVEs: CSCun02887, CSCur00115, CSCur00127)

Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Local
666
CVE-2015-4231
Cisco NX-OS 6.2(8a) allows an admin in one VDC to delete files in another VDC

The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Local
665
CVE-2012-0860
Untrusted search path in RHEV-M 3.1 allows local users to gain privileges via malicious Python modules in /tmp when adding a host

Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Local
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::