← All CVEs

CVE-2007-4965

medium · 5.8

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

5.8
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2007-09-18
Published

AV:N/AC:M/Au:N/C:P/I:N/A:P

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
pythonpython<= 2.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-4965