Package impact

python PyPI / numpy

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2017-12852 high 7.5 7.5 9y ago The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack. susepython
CVE-2019-6446 medium 5.5 4y ago Moderate: python27:2.7 security and bug fix update suserockylinuxpython
CVE-2014-1858 unknown 4y ago __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file. python
CVE-2014-1859 unknown 4y ago (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink at… python
CVE-2021-41496 unknown 4y ago Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative val… susedebianpython
CVE-2021-41495 unknown 4y ago Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attack… susedebianpython
CVE-2021-33430 unknown 4y ago A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a mali… susedebianpython
CVE-2021-34141 unknown 5y ago Incomplete string comparison in the numpy.core component in NumPy1.9.x, which allows attackers to fail the APIs via constructing specific string objects. susedebianpython