← All CVEs

CVE-2014-1912

high · 7.5

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

7.5
CVSS
28.3%
EPSS (exploit prob.)
98th
EPSS percentile
2014-03-01
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
pythonpython2.5.1
pythonpython2.5.2
pythonpython2.5.3
pythonpython2.5.4
pythonpython2.5.6
pythonpython2.5.150
pythonpython2.6.1
pythonpython2.6.2
pythonpython2.6.3
pythonpython2.6.4
pythonpython2.6.5
pythonpython2.6.6
pythonpython2.6.7
pythonpython2.6.8
pythonpython2.6.2150
pythonpython2.6.6150
pythonpython2.7.1
pythonpython2.7.1
pythonpython2.7.2
pythonpython2.7.3
pythonpython2.7.4
pythonpython2.7.5
pythonpython2.7.6
pythonpython2.7.1150
pythonpython2.7.1150
pythonpython2.7.2150
applemac_os_x<= 10.10.4
pythonpython3.0
pythonpython3.0.1
pythonpython3.1
pythonpython3.1.1
pythonpython3.1.2
pythonpython3.1.3
pythonpython3.1.4
pythonpython3.1.5
pythonpython3.1.2150
pythonpython3.2
pythonpython3.2
pythonpython3.2.0
pythonpython3.2.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-1912