VAITP Dataset

Dataset Statistics
Search for CVE
#
CVE
Vulnerability
ODC
Category
Subcategory
Accessibility Scope
Details
Total vulnerabilities in the dataset (not showing ignored and non-python related vulnerabilties): 1890
489
Untrusted search path in gedit allows local code execution via a malicious Python file in the current directory

Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

Function
Input Validation and Sanitization
Path Traversal
Local
488
Flask-Unchained <0.9.0 allows URL bypass via backslashes

This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.

Function
Configuration Issues
Open Redirects
Remote
487
Meinheld (prior to 1.0.2) vulnerable to HTTP Request Smuggling via incorrect parsing of headers

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
486
File overwrite in TensorFlow 2.5.0 via tf.keras.utils.get_file (extract=True), not for untrusted archives

** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.

Function
Input Validation and Sanitization
Path Traversal
Local
485
Remote authenticated users execute arbitrary Python code via sandbox whitelisting in Plone before 4.2.3 and 4.3 beta 1

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

Function
Authentication, Authorization, and Session Management
Privilege Escalation
Remote
484
Orca Python module loading allows arbitrary code execution

Orca has arbitrary code execution due to insecure Python module load

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
483
Python-keystoneclient 0.2.3 to 0.2.5: Middleware memcache signing bypass vulnerability

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
482
Python-keystoneclient 0.2.3 to 0.2.5 allows memcache encryption bypass

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
480
Arbitrary OS command execution via untrusted Bikeshed Inline Tag Command metadata (pre-3.0.0)

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

Function
Input Validation and Sanitization
Command Injection
Remote
479
Vulnerability in qlib's workflow: Unsafe YAML load

This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Local
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::