Known vulnerabilities in Python 3.4

Vendor: Python.org
Software: Python
Version: 3.4
Software CPE: cpe:2.3:a:python_org:python:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Python version 3.4 Python 3.4 is affected by 16 vulnerabilities: 5 high, 9 medium, 2 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113029 - Integer overflow
CVE-2016-5636
CWE-190 High
No
No
2.7.12, 3.4.5, 3.5.2 17.07.2025 SB2016090207
#VU111970 - Expected Behavior Violation
CVE-2025-4435
CWE-440 Low
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 59 more
#VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12718
CWE-22 Medium
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 62 more
#VU111968 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4138
CWE-59 High
Public exploit available
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 64 more
#VU111967 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4330
CWE-59 High
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 63 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Public exploit available
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more
#VU100516 - Improper input validation
CVE-2024-11168
CWE-20 Medium
No
No
3.11.5 15.11.2024 SB2024111507
SB2024111526
SB2024111527
and 76 more
#VU67591 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-28861
CWE-601 Low
No
No
3.7.14, 3.8.14, 3.9.14, 3.10.6 22.09.2022 SB2022092243
SB2022092244
SB2022093032
and 76 more
#VU50621 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-27619
CWE-94 Medium
No
No
3.9.1 11.02.2021 SB2020112330
SB2021032307
SB2021032607
and 24 more
#VU49973 - Memory corruption
CVE-2021-3177
CWE-119 High
No
No
- 19.01.2021 SB2021012516
SB2021012517
SB2021022418
and 54 more
#VU110145 - Improper input validation
CVE-2013-1753
CWE-20 Medium
No
No
- 21.10.2020 SB2020102152
SB20200930128
#VU48592 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26116
CWE-93 Medium
No
No
3.5.10, 3.6.12, 3.7.9, 3.8.5 27.09.2020 SB2020092711
SB2020112308
SB2020112309
and 34 more
#VU110148 - Improper input validation
CVE-2013-4238
CWE-20 Medium
No
No
- 25.10.2019 SB2019102514
#VU31958 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2019-18348
CWE-74 Medium
No
No
2.7.18, 3.8.1 23.10.2019 SB2019102324
SB2020052312
SB2020042173
and 13 more
#VU18829 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-9740
CWE-93 Medium
No
No
- 19.06.2019 SB2019031318
SB2019062812
SB2019072603
and 32 more
#VU18828 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-9947
CWE-93 Medium
No
No
- 19.06.2019 SB2019031318
SB2019062812
SB2019072603
and 22 more