Stan Ulbrych
36 exploits
Active since Jun 2024
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
pkgutil.get_data() does not enforce documented restrictions
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Incomplete control character validation in http.cookies
CVSS 7.5
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
pkgutil.get_data() does not enforce documented restrictions
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook