Seth Michael Larson
113 exploits
Active since Mar 2020
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
Python <3.10.14-3.13.0a5 - Memory Corruption
CVSS 7.4
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
Python <3.14 - Path Traversal
CVSS 9.4
Python CPython - HTTP Header Injection
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
Python <3.14 - Path Traversal
CVSS 9.4
Python CPython - HTTP Header Injection
Python <3.10.14-3.13.0a5 - Memory Corruption
CVSS 7.4
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython urllib.parse - Bracketed Host Validation Bypass
CPython HTTP Header Injection via Email Header Folding