Python Pillow 9.1.0

CPE Details

Python Pillow 9.1.0
9.1.0
2022-05-31
15h37 +00:00
2022-10-24
12h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:python:pillow:9.1.0:*:*:*:*:*:*:*

Informations

Vendor

python

Product

pillow

Version

9.1.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-50447 2024-01-18 23h00 +00:00 Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
8.1
High
CVE-2023-44271 2023-11-02 23h00 +00:00 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
7.5
High
CVE-2022-45198 2022-11-13 23h00 +00:00 Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
7.5
High
CVE-2022-45199 2022-11-13 23h00 +00:00 Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
7.5
High
CVE-2022-30595 2022-05-25 09h46 +00:00 libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
9.8
Critical