Python Exploits

5,949 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112050 EXPLOITDB python VERIFIED
SilverStripe CMS 2.4.7 - 'install.php' PHP Code Injection
by Mehmet Ince
EIP-2026-104602 EXPLOITDB python
Microsoft Office 2008 SP0 (Mac) - RTF pFragments
by Abhishek Lyall
EIP-2026-103981 EXPLOITDB python VERIFIED
McAfee Web Gateway 7.1.5.x - 'Host' HTTP Header Security Bypass
by Gabriel Menezes Nunes
CVE-2012-2095 EXPLOITDB python VERIFIED
David Paleino Wicd < 1.7.1 - Improper Input Validation
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.
by anonymous
CVE-2014-9448 EXPLOITDB python VERIFIED
Mini-stream RM-MP3 Converter <3.1.2.1.2010.03.30 - Buffer Overflow
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long string in a WAX file.
by SkY-NeT SySteMs
EIP-2026-116595 EXPLOITDB python VERIFIED
Xion Audio Player 1.0.127 - '.aiff' Denial of Service
by condis
CVE-2012-10031 EXPLOITDB HIGH python
BlazeVideo HDTV Player Pro v6.6.0.3 - Buffer Overflow
BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a filename from a URL-like string. The returned value is then copied to a fixed-size stack buffer using an inline strcpy call without bounds checking. If the input exceeds the buffer size, this leads to a stack overflow and potential arbitrary code execution under the context of the user.
by b33f
EIP-2026-119197 EXPLOITDB python VERIFIED
Sysax 5.57 - Directory Traversal
by Craig Freyman
EIP-2026-118753 EXPLOITDB python
MailMax 4.6 - POP3 'USER' Remote Buffer Overflow
by localh0t
EIP-2026-103632 EXPLOITDB python
PHP 5.4.0 Built-in Web Server - Denial of Service (PoC)
by ls
EIP-2026-116313 EXPLOITDB python
Spotify 0.8.2.610 - search func Memory Exhaustion
by LiquidWorm
CVE-2012-4869 EXPLOITDB python VERIFIED
FreePBX <2.10 - Command Injection
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.
by muts
CVE-2015-6750 EXPLOITDB python VERIFIED
Ricoh Dl-1 Sr10 < 1.1.0.6 - Memory Corruption
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.
by Julien Ahrens
CVE-2012-4864 EXPLOITDB python
Oreans WinLicense 2.1.8.0 - Memory Corruption, DoS
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted xml file.
by LiquidWorm
EIP-2026-116410 EXPLOITDB python VERIFIED
Tiny Server 1.1.9 - HEAD Denial of Service
by brock haun
EIP-2026-116053 EXPLOITDB python
PeerFTP Server 4.01 - Remote Crash (PoC)
by localh0t
CVE-2012-5329 EXPLOITDB python VERIFIED
TYPSoft FTP Server 1.1 - DoS
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.
by brock haun
CVE-2012-5329 EXPLOITDB python
TYPSoft FTP Server 1.1 - DoS
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.
by brock haun
EIP-2026-115931 EXPLOITDB python VERIFIED
Network Instrument Observer - SNMP SetRequest Denial of Service
by Francis Provencher
EIP-2026-117432 EXPLOITDB python VERIFIED
Macro Toolworks 7.5 - Local Buffer Overflow
by Julien Ahrens
EIP-2026-118479 EXPLOITDB python
EasyFTP Server 1.7.0.11 - 'APPE' Remote Buffer Overflow
by Swappage
CVE-2012-1464 EXPLOITDB python VERIFIED
Netmechanica Netdecision < 4.5.1 - Information Disclosure
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent resource. NOTE: some of these details are obtained from third party information.
by SecPod Research
CVE-2012-1465 EXPLOITDB python VERIFIED
Netmechanica Netdecision < 4.5.1 - Memory Corruption
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party information.
by SecPod Research
CVE-2012-1096 EXPLOITDB MEDIUM python VERIFIED
NetworkManager <0.9 - Privilege Escalation
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
by Ludwig
CVSS 5.5
CVE-2012-10060 EXPLOITDB CRITICAL python VERIFIED
Sysax Multi Server <5.55 - Buffer Overflow
Sysax Multi Server versions prior to 5.55 contains a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execution under the context of the service.
by Craig Freyman
CVSS 9.8