Miss Islington (bot)
160 exploits
Active since Jun 2019
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
Incomplete control character validation in http.cookies
CVSS 7.5
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
CPython >3.11 Insecure Input Validation resulting in privilege escalation
tarfile extraction filter bypass allows escaping the destination directory
Configuration Injection via Carriage Return (\r) in write() method
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CPython < 3.15.0a6 - Command Injection via IMAP Command Newline Injection
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
Incomplete control character validation in http.cookies
CVSS 7.5