Threats Tagged 'cve-2024-9287'
View all threats tagged with 'cve-2024-9287'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-9287'
Click on any threat for detailed analysis and mitigation recommendations
0 The Red Hat Storage Ceph container images are based on the latest ubi9 base image and Ceph 8.1. This release updates to the latest version. Join the discussion | GCVE Database | 02/02/2026, 02:51:27 UTC Added: 05/26/2026, 20:58:20 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 01/08/2026, 22:34:17 UTC Added: 05/26/2026, 20:58:24 UTC |
This advisory covers a bug fix and enhancement update for python3.12 on Red Hat Enterprise Linux 10. It addresses multiple security issues including a ReDos vulnerability (CVE-2024-6232) in the tarfile module due to excessive backtracking while parsing header values. The update is provided as a bug fix advisory with no explicit security fixes listed for python3.12 in this release, but it includes references to related CVEs. The update affects various Red Hat Enterprise Linux 10 and CodeReady Linux Builder 10 variants across multiple architectures. No known exploits are reported in the wild. The update is available and should be applied according to Red Hat's guidance. Join the discussion | GCVE Database | 05/13/2025, 08:08:03 UTC Added: 06/25/2026, 21:47:26 UTC |
0 CVE-2024-9287 is a vulnerability in the Python CPython venv module where activation scripts do not properly quote path names. This allows an attacker who creates a malicious virtual environment to inject commands that execute when the environment is activated using the 'source venv/bin/activate' command. Virtual environments created by trusted users or those used without activation (e.g., directly invoking the Python binary) are not affected. The issue affects multiple Python versions from 3.6.8 through versions prior to fixed releases in 3.9.21, 3.10.16, 3.11.11, 3.12.8, and 3.13.1. A patch is available and has been issued by Red Hat and other vendors. The severity is assessed as medium. Join the discussion | GCVE Database | 12/13/2024, 12:39:42 UTC Added: 06/25/2026, 21:47:45 UTC |
0 Red Hat has issued a security advisory for python3.12 addressing two vulnerabilities: CVE-2024-9287, where virtual environment activation scripts do not quote paths, and CVE-2024-12254, involving unbounded memory buffering in SelectorSocketTransport.writelines(). These issues affect Red Hat Enterprise Linux 9.4 Extended Update Support and related variants. The advisory rates the update as important and provides updated packages to remediate the vulnerabilities. Join the discussion | GCVE Database | 12/13/2024, 09:19:06 UTC Added: 06/25/2026, 21:47:43 UTC |
0 Red Hat has issued a security advisory for python3.12 addressing two vulnerabilities: CVE-2024-9287, where virtual environment activation scripts do not quote paths, and CVE-2024-12254, involving unbounded memory buffering in SelectorSocketTransport.writelines(). These issues affect Red Hat Enterprise Linux 8 and related variants. The advisory rates the update as important and provides updated packages to remediate these vulnerabilities. Join the discussion | GCVE Database | 12/12/2024, 08:56:14 UTC Added: 06/25/2026, 21:47:43 UTC |
A security vulnerability (CVE-2024-9287) affecting Python 3.11 versions prior to 3.11.7 has been identified. The issue involves virtual environment (venv) activation scripts not quoting paths properly, which could lead to security concerns. Red Hat has issued an advisory and released updates for Red Hat Enterprise Linux 9.4 Extended Update Support and related products to address this vulnerability. The severity is rated as moderate. No CVSS score is provided. No known exploits in the wild have been reported. Join the discussion | GCVE Database | 12/12/2024, 08:56:14 UTC Added: 06/25/2026, 21:47:21 UTC |
0 Red Hat has issued a security advisory for python3.12 addressing two vulnerabilities: CVE-2024-9287, where virtual environment activation scripts do not quote paths, and CVE-2024-12254, involving unbounded memory buffering in SelectorSocketTransport.writelines(). These issues affect Red Hat Enterprise Linux 9 and related distributions. The update is rated as Important by Red Hat Product Security. No CVSS score is provided in the advisory. The update is available and users are advised to apply it according to Red Hat's guidance. Join the discussion | GCVE Database | 12/12/2024, 08:42:34 UTC Added: 06/25/2026, 21:47:43 UTC |
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5. Join the discussion | GCVE Database | 06/17/2024, 16:15:00 UTC Added: 06/25/2026, 21:47:43 UTC |
Showing 1 to 9 of 9 results