2.2.1
18 years ago
1 days ago
Known vulnerabilities in the numpy package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
numpy is a fundamental package needed for scientific computing with Python. Affected versions of this package are vulnerable to Buffer Overflow in the How to fix Buffer Overflow? Upgrade | [,1.21.0rc1) |
numpy is a fundamental package needed for scientific computing with Python. Affected versions of this package are vulnerable to Buffer Overflow due to missing boundary checks in the How to fix Buffer Overflow? Upgrade | [,1.22.0) |
numpy is a fundamental package needed for scientific computing with Python. Affected versions of this package are vulnerable to NULL Pointer Dereference due to missing return-value validation in the Note: This may likely only happen if application memory is already exhausted, as it requires the How to fix NULL Pointer Dereference? Upgrade | [0,1.22.2) |
numpy is a fundamental package needed for scientific computing with Python. Affected versions of this package are vulnerable to Denial of Service (DoS) due to an incomplete string comparison in the How to fix Denial of Service (DoS)? Upgrade | [,1.22.0rc1) |
numpy is a fundamental package needed for scientific computing with Python. Affected versions of this package are vulnerable to Arbitrary Code Execution. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a PoC by nanshihui:
How to fix Arbitrary Code Execution? Upgrade | [0,1.16.3) |
numpy is a package needed for scientific computing with Python. Affected versions of this package are vulnerable to Symlink Attack. It allows local users to write to arbitrary files via a symlink attack on a temporary file. How to fix Symlink Attack? Upgrade | [,1.8.2) |
numpy is a package for scientific computing with Python. Affected versions of this package are vulnerable to Denial of Service (DoS)due to missing input validation. An empty list or an array will stick into an infinite loop. How to fix Denial of Service (DoS)? Upgrade | [,1.13.3) |
| [,1.8.1) |