Pythonware Python Imaging Library vulnerabilities
3 known vulnerabilities affecting pythonware/python_imaging_library.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2014-3007CRITICALCVSS 10.0≤ 1.1.72014-04-27
CVE-2014-3007 [CRITICAL] CVE-2014-3007: Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.
nvd
CVE-2014-1932MEDIUMCVSS 4.4≤ 1.1.72014-04-17
CVE-2014-1932 [MEDIUM] CWE-59 CVE-2014-1932: The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sens
nvd
CVE-2014-1933LOWCVSS 2.1≤ 1.1.72014-04-17
CVE-2014-1933 [LOW] CWE-264 CVE-2014-1933: The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.
nvd