Known vulnerabilities in python-pillow
Vendor:
Fedoraproject
Software:
python-pillow
Software CPE:
cpe:2.3:o:fedoraproject:python-pillow:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
42
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.3.0-10.fc43
12.3.0-1.fc44
11.3.0-9.fc43
12.2.0-1.fc44
11.3.0-8.fc43
11.1.0-3.fc42
11.3.0-7.fc43
7.0.0-4.fc32
6.2.2-3.fc31
5.4.1-4.fc30
6.2.2-1.fc31
5.4.1-3.fc30
6.1.0-4.fc31
3.0.0-6.fc23
3.2.0-3.fc24
3.2.0-2.fc24
3.0.0-5.fc23
2.8.2-5.fc22
3.0.0-4.fc23
2.8.2-4.fc22
2.8.2-3.fc22
3.0.0-2.fc23
2.6.1-2.fc21
8.1.2-7.fc34
8.3.2-3.fc35
9.0.1-6.fc36
9.0.1-5.fc36
8.3.2-2.fc35
8.1.2-6.fc34
7.2.0-8.fc33
8.1.2-5.fc34
8.1.2-4.fc34
7.2.0-7.fc33
7.2.0-6.fc33
8.1.2-3.fc34
7.2.0-5.fc33
8.1.2-1.fc34
7.0.0-7.fc32
7.2.0-4.fc33
7.0.0-6.fc32
7.0.0-5.fc32
7.2.0-3.fc33
10.3.0-1.fc39
9.5.0-3.fc38
9.5.0-2.fc38
9.5.0-1.fc38
Vulnerabilities (42)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137006 - Out-of-bounds read CVE-2026-54058 |
CWE-125 | High | 11.3.0-10.fc43 | 07.07.2026 |
SB2026070342 SB2026071741 SB2026071949 and 12 more |
||
| #VU137005 - Heap-based Buffer Overflow CVE-2026-59197 |
CWE-122 | High | 11.3.0-10.fc43 | 07.07.2026 |
SB2026041113 SB2026071741 SB2026071949 and 12 more |
||
| #VU136861 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-55798 |
CWE-78 | Medium | 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 1 more |
||
| #VU136860 - Uncontrolled Memory Allocation CVE-2026-55379 |
CWE-789 | Medium | 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136859 - Uncontrolled Memory Allocation CVE-2026-54059 |
CWE-789 | Medium | 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136858 - Uncontrolled Memory Allocation CVE-2026-54060 |
CWE-789 | Medium | 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136857 - Uncontrolled Memory Allocation CVE-2026-55380 |
CWE-789 | Medium | 11.3.0-9.fc43, 11.3.0-10.fc43, 12.3.0-1.fc44 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU125817 - Resource exhaustion CVE-2026-40192 |
CWE-400 | Medium | 11.3.0-8.fc43, 12.2.0-1.fc44 | 11.04.2026 |
SB2026041113 SB2026041807 SB2026041808 and 8 more |
||
| #VU123113 - Out-of-bounds write CVE-2026-25990 |
CWE-787 | High | 11.1.0-3.fc42, 11.3.0-7.fc43 | 20.02.2026 |
SB2026022027 SB2026022028 SB2026022035 and 12 more |
||
| #VU88063 - Memory corruption CVE-2024-28219 |
CWE-119 | Medium | 10.3.0-1.fc39 | 03.04.2024 |
SB2024040318 SB2024040320 SB2024040844 and 28 more |
||
| #VU85743 - Improper Control of Generation of Code ('Code Injection') CVE-2023-50447 |
CWE-94 | High | 9.5.0-3.fc38 | 24.01.2024 |
SB2024012413 SB2024012417 SB2024012465 and 34 more |
||
| #VU83261 - Resource exhaustion CVE-2023-44271 |
CWE-400 | Medium | 9.5.0-1.fc38, 9.5.0-2.fc38, 9.5.0-3.fc38 | 18.11.2023 |
SB2023111809 SB2023111810 SB2023111811 and 25 more |
||
| #VU69497 - Improper input validation CVE-2022-24303 |
CWE-20 | Medium | 8.1.2-7.fc34, 8.3.2-3.fc35, 9.0.1-6.fc36 | 22.11.2022 |
SB2022112229 SB2022112234 SB2022121360 and 6 more |
||
| #VU68608 - Incorrect Regular Expression CVE-2021-23437 |
CWE-185 | Medium | 7.2.0-8.fc33, 8.1.2-5.fc34 | 24.10.2022 |
SB2021090323 SB2022102434 SB2022112234 and 8 more |
||
| #VU68607 - Memory corruption CVE-2021-34552 |
CWE-119 | High | 7.2.0-7.fc33, 8.1.2-4.fc34 | 24.10.2022 |
SB2022102431 SB2022102434 SB2022112234 and 9 more |
||
| #VU60003 - Exposed Dangerous Method or Function CVE-2022-22817 |
CWE-749 | High | 8.1.2-6.fc34, 8.3.2-2.fc35 | 25.01.2022 |
SB2022012523 SB2022012526 SB2022022226 and 26 more |
||
| #VU60002 - Out-of-bounds read CVE-2022-22816 |
CWE-125 | Medium | 8.1.2-6.fc34, 8.3.2-2.fc35 | 25.01.2022 |
SB2022012523 SB2022012526 SB2022022226 and 33 more |
||
| #VU60001 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-22815 |
CWE-22 | Medium | 8.1.2-6.fc34, 8.3.2-2.fc35 | 25.01.2022 |
SB2022012523 SB2022012526 SB2022102434 and 24 more |
||
| #VU52191 - Improper input validation CVE-2021-28677 |
CWE-20 | Medium | 7.2.0-6.fc33, 8.1.2-3.fc34 | 13.04.2021 |
SB2021041363 SB2021051947 SB2024051101 and 3 more |
||
| #VU52189 - Resource Management Errors CVE-2021-28675 |
CWE-399 | Medium | 7.2.0-6.fc33, 8.1.2-3.fc34 | 13.04.2021 |
SB2021041363 SB2021051947 SB2024051101 and 3 more |
Showing elements 1 - 20 out of 42