Miss Islington (bot)
125 exploits
Active since Jun 2019
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
HTTP client proxy tunnel headers not validated for CR/LF
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
HTTP client proxy tunnel headers not validated for CR/LF
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
Python 2.7.0-2.7.16, 3.5, 3.6, 3.7, 3.8.0a4-3.8.0b1 - URL Parsing Security Regression
CVSS 9.8
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
Python 2.7.0-2.7.16, 3.5, 3.6, 3.7, 3.8.0a4-3.8.0b1 - URL Parsing Security Regression
CVSS 9.8
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython < 3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.3, 3.13.0a1 - Incorrect Default Permissions
CVSS 7.1
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race