Seth Michael Larson
113 exploits
Active since Mar 2020
Python urllib.request - Data URL Header Injection
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
Python <3.14 - Path Traversal
CVSS 9.4
Python CPython - HTTP Header Injection
CPython 3.12-3.12.10, 3.13-3.13.3, 3.14a1-3.14b2 - Path Traversal via TarFile Extraction Filter
CVSS 5.3
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython urllib.parse - Bracketed Host Validation Bypass
CPython HTTP Header Injection via Email Header Folding
Python urllib.request - Data URL Header Injection
Python CPython - HTTP Header Injection
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython urllib.parse - Bracketed Host Validation Bypass
CPython HTTP Header Injection via Email Header Folding
Python urllib.request - Data URL Header Injection
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
Python <3.14 - Path Traversal
CVSS 9.4
Python CPython - HTTP Header Injection
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython urllib.parse - Bracketed Host Validation Bypass