Seth Michael Larson
113 exploits
Active since Mar 2020
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython HTTP Header Injection via http.cookies.Morsel
Python CPython - HTTP Header Injection
CPython email module - CRLF Injection in BytesGenerator Header Serialization
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython HTTP Header Injection via http.cookies.Morsel
Python CPython - HTTP Header Injection
CPython email module - CRLF Injection in BytesGenerator Header Serialization
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython HTTP Header Injection via http.cookies.Morsel
Python CPython - HTTP Header Injection
CPython email module - CRLF Injection in BytesGenerator Header Serialization
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
urllib3 < 1.25.9 - CRLF Injection via HTTP Request Method
CVSS 6.5
urllib3 1.25.2-1.25.7 - Denial of Service via Inefficient Percent-Encoding Algorithm
CVSS 7.5
urllib3 >=1.25.4 <1.26.5 - Denial of Service via Authority Component Regex Backtracking
CVSS 7.5
urllib3 <1.26.17, <2.0.5 - Info Disclosure
CVSS 5.9
CPython <3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.4, 3.13.0a1-3.13.0rc0 - Socket Connection Race