Serhiy Storchaka
20 exploits
Active since Oct 2020
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Base64 decoding stops at first padded quad by default
Python <3.9.0 - Code Injection
CVSS 9.8
CPython <3.12.1-3.8.18 - Use After Free
CVSS 7.8
CPython <3.12.1-3.8.18 - Zip Bomb
CVSS 6.2
CPython - Code Injection
CVSS 5.5
CPython - Info Disclosure
CVSS 7.5
base64 module - Info Disclosure
CVSS 5.3
Python < 3.13.11 - Denial of Service
CVSS 7.5
Python < 3.13.10 - Denial of Service
CVSS 5.5
Python TarFile < - Path Traversal
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
CPython - Info Disclosure
html.parser - DoS
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
Zipfile - Buffer Overflow
CVSS 4.3