0.0.32
3 years ago
1 months ago
Known vulnerabilities in the picklescan package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the How to fix Deserialization of Untrusted Data? Upgrade | [,0.0.31) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Protection Mechanism Failure via the How to fix Protection Mechanism Failure? Upgrade | [,0.0.31) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Protection Mechanism Failure when processing ZIP files. An attacker can bypass detection of malicious payloads by crafting ZIP archives with invalid CRC values, causing the scan to fail and return no results while still allowing other tools to load the contents. How to fix Protection Mechanism Failure? Upgrade | [,0.0.31) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Protection Mechanism Failure via the How to fix Protection Mechanism Failure? Upgrade | [,0.0.31) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to using How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to using How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to using the How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to insufficient detection in the How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to the use of How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to insufficient detection in the How to fix Remote Code Execution (RCE)? Upgrade | [,0.0.28) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the How to fix Deserialization of Untrusted Data? Upgrade | [,0.0.27) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in How to fix Incomplete List of Disallowed Inputs? Upgrade | [,0.0.25) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Deserialization of Untrusted Data in How to fix Deserialization of Untrusted Data? Upgrade | [,0.0.25) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in How to fix Incomplete List of Disallowed Inputs? Upgrade | [,0.0.25) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity when PickleScan attempts to extract and scan PyTorch model archives, an attacker can manipulate the How to fix Insufficient Verification of Data Authenticity? Upgrade | [,0.0.23) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity due to improper handling of modified How to fix Insufficient Verification of Data Authenticity? Upgrade | [,0.0.23) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Reliance on File Name or Extension of Externally-Supplied File due to insufficient scanning of non-standard pickle file extensions. How to fix Reliance on File Name or Extension of Externally-Supplied File? Upgrade | [,0.0.22) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs which does not include How to fix Incomplete List of Disallowed Inputs? Upgrade | [,0.0.21) |
picklescan is a Security scanner detecting Python Pickle files performing suspicious actions Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to improper argument verification when handling a memo, making it possible to have a different memo and use How to fix Deserialization of Untrusted Data? Upgrade | [,0.0.13) |