Known vulnerabilities in python (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
16
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.6.6-70.el6_10.4
2.7.5-94.el7_9.5
2.6.6-70.el6_10.3
2.7.5-94.el7_9.4
2.6.6-70.el6_10.2
2.7.5-94.el7_9.3
2.7.5-94.el7_9.2
2.4.3-46.el5_8.2
2.6.6-29.el6_2.2
2.3.4-14.7.el4_8.2
2.4.3-24.el5_3.6
2.3.4-14.4.el4_6.1
2.7.5-94.el7_9
2.6.6-70.el6_10
2.7.5-93.el7_9
2.6.6-69.el6_10
2.7.5-84.el7_6
2.7.5-64.el7_4
2.7.5-88.el7_7
2.7.5-90.el7
2.7.5-89.el7
2.7.5-87.el7_7
2.7.5-83.el7_6
2.7.5-63.el7_4
2.7.5-74.el7_5
2.7.5-88.el7
2.7.5-59.el7_4
2.7.5-70.el7_5
2.7.5-86.el7
2.7.5-80.el7_6
2.7.5-77.el7_6
2.7.5-76.el7
2.7.5-69.el7_5
2.7.5-58.el7
2.4.3-43.el5
2.3.4-14.9.el4
2.3.4-14.10.el4
2.4.3-44.el5
2.7.5-34.el7
2.7.5-38.el7_2
2.7.5-48.el7
2.6.6-68.el6_10
2.6.6-66.el6_8
2.6.6-64.el6
2.6.6-52.el6
2.6.6-51.el6
2.6.6-37.el6_4
2.6.6-36.el6
2.6.6-29.el6_3
2.6.6-29.el6_2
2.6.6-29.el6
2.6.6-20.el6
2.6.5-3.el6_0
2.6.5-3.el6
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122819 - Command injection CVE-2025-15367 |
CWE-77 | Medium | 2.6.6-70.el6_10.2, 2.7.5-94.el7_9.3 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 56 more |
||
| #VU122818 - Command injection CVE-2025-15366 |
CWE-77 | Medium | 2.6.6-70.el6_10.2, 2.7.5-94.el7_9.3 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 52 more |
||
| #VU119238 - Inefficient Algorithmic Complexity CVE-2025-12084 |
CWE-407 | Low | 2.7.5-94.el7_9.2 | 06.12.2025 |
SB2025120606 SB20251226352 SB2025123104 and 48 more |
||
| #VU80228 - Cleartext Transmission of Sensitive Information CVE-2023-40217 |
CWE-319 | Medium | 2.6.6-70.el6_10, 2.7.5-94.el7_9 | 01.09.2023 |
SB2023090142 SB2023090143 SB2023090144 and 139 more |
||
| #VU72618 - Improper input validation CVE-2023-24329 |
CWE-20 | Medium | 2.6.6-69.el6_10, 2.7.5-93.el7_9 | 28.02.2023 |
SB2023022819 SB2023022822 SB2023030832 and 158 more |
||
| #VU32881 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2019-20907 |
CWE-835 | Medium | 2.7.5-64.el7_4, 2.7.5-84.el7_6, 2.7.5-88.el7_7, 2.7.5-90.el7 | 29.07.2020 |
SB2020071324 SB2020080201 SB2020082408 and 53 more |
||
| #VU22617 - Improper input validation CVE-2019-16056 |
CWE-20 | Low | 2.7.5-87.el7_7, 2.7.5-88.el7 | 10.11.2019 |
SB2019111003 SB2019111004 SB2019110649 and 31 more |
||
| #VU21440 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-16935 |
CWE-79 | Medium | 2.7.5-89.el7 | 30.09.2019 |
SB2019093008 SB2019111003 SB2019111004 and 24 more |
||
| #VU19256 - Exposure of sensitive information to an unauthorized actor CVE-2018-20852 |
CWE-200 | Medium | 2.7.5-88.el7 | 19.07.2019 |
SB2019071301 SB2019082304 SB2019082305 and 16 more |
||
| #VU18829 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2019-9740 |
CWE-93 | Medium | 2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 | 19.06.2019 |
SB2019031318 SB2019062812 SB2019072603 and 32 more |
||
| #VU18828 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2019-9947 |
CWE-93 | Medium | 2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 | 19.06.2019 |
SB2019031318 SB2019062812 SB2019072603 and 22 more |
||
| #VU18827 - Exposed Dangerous Method or Function CVE-2019-9948 |
CWE-749 | Medium | 2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 | 19.06.2019 |
SB2019031318 SB2019061903 SB2019042504 and 18 more |
||
| #VU15760 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2018-14647 |
CWE-611 | Low | 2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 | 08.11.2018 |
SB2018110808 SB2018122106 SB2018092802 and 35 more |
||
| #VU12283 - Improper input validation CVE-2018-1060 |
CWE-20 | Medium | 2.7.5-63.el7_4, 2.7.5-74.el7_5 | 27.04.2018 |
SB2018042706 SB2018111109 SB2018120712 and 36 more |
||
| #VU12282 - Improper input validation CVE-2018-1061 |
CWE-20 | Medium | 2.7.5-63.el7_4, 2.7.5-74.el7_5 | 27.04.2018 |
SB2018042706 SB2018111109 SB2018120712 and 20 more |
||
| #VU33825 - Improper input validation CVE-2014-9365 |
CWE-20 | Medium | 2.7.5-58.el7 | 12.12.2014 |
SB2014121206 SB2015080503 SB2015031809 and 1 more |