cbcvebase.
CVE-2014-3007
published 2014-04-27

CVE-2014-3007: Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified…

PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
12.05%
95.7th percentile
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianpillow< pillow 2.4.0-1 (bookworm)pillow 2.4.0-1 (bookworm)
pythonpillow
pythonpillow>= 0 < 2.4.0-12.4.0-1
pythonpillow>= 0 < 2.4.0-12.4.0-1
pythonpillow>= 0 < 2.4.0-12.4.0-1
pythonpillow>= 0 < 2.4.0-12.4.0-1
pythonpillow>= 0 < 2.5.02.5.0
pythonwarepython_imaging_library<= 1.1.7

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
ghsa4.4MEDIUM
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.