Vulnerability Details CVE-2014-3539
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2014-3539
-
cpe:2.3:a:rope_project:rope:0.10.0
-
cpe:2.3:a:rope_project:rope:0.10.1
-
cpe:2.3:a:rope_project:rope:0.10.2
-
cpe:2.3:a:rope_project:rope:0.10.4
-
cpe:2.3:a:rope_project:rope:0.10.5
-
cpe:2.3:a:rope_project:rope:0.10.6
-
cpe:2.3:a:rope_project:rope:0.10.7
-
cpe:2.3:a:rope_project:rope:0.7
-
cpe:2.3:a:rope_project:rope:0.7.1
-
cpe:2.3:a:rope_project:rope:0.7.2
-
cpe:2.3:a:rope_project:rope:0.7.3
-
cpe:2.3:a:rope_project:rope:0.7.4
-
cpe:2.3:a:rope_project:rope:0.7.5
-
cpe:2.3:a:rope_project:rope:0.7.6
-
cpe:2.3:a:rope_project:rope:0.7.7
-
cpe:2.3:a:rope_project:rope:0.7.8
-
cpe:2.3:a:rope_project:rope:0.7.9
-
cpe:2.3:a:rope_project:rope:0.8
-
cpe:2.3:a:rope_project:rope:0.8.1
-
cpe:2.3:a:rope_project:rope:0.8.2
-
cpe:2.3:a:rope_project:rope:0.8.3
-
cpe:2.3:a:rope_project:rope:0.8.4
-
cpe:2.3:a:rope_project:rope:0.9
-
cpe:2.3:a:rope_project:rope:0.9.1
-
cpe:2.3:a:rope_project:rope:0.9.2
-
cpe:2.3:a:rope_project:rope:0.9.3
-
cpe:2.3:a:rope_project:rope:0.9.4