← Back to News Iceland Security Dashboard Browse all tags
picklescan

Picklescan

picklescan 19

CVEs tagged with this vendor (19)

CVE-2025-71341 CVSS 8.1
CVE-2025-71341 is a deserialization vulnerability in picklescan versions prior to 0.0.29 that fails to detect the profile.Profile.runctx function within pickle …
CVE-2025-71342 CVSS 8.1
CVE-2025-71342 is a high-severity deserialization vulnerability in picklescan versions prior to 0.0.30 that fails to detect malicious pickle files containing un…
CVE-2025-71343 CVSS 8.1
CVE-2025-71343 affects picklescan versions prior to 0.0.30, which fail to detect malicious pickle files exploiting the lib2to3.pgen2.pgen.ParserGenerator.make_l…
CVE-2025-71345 CVSS 8.1
picklescan versions prior to 0.0.30 fail to detect malicious pickle files invoking the torch.utils.bottleneck.__main__.run_autograd_prof function, allowing atta…
CVE-2025-71353 CVSS 8.1
CVE-2025-71353 affects picklescan versions prior to 0.0.28, which fail to detect malicious pickle files exploiting the torch._dynamo.guards.GuardBuilder.get fun…
CVE-2025-71354 CVSS 8.1
CVE-2025-71354 affects picklescan versions prior to 0.0.29, which fail to detect malicious pickle files exploiting the idlelib.debugobj.ObjectTreeItem.SetText f…
CVE-2025-71359 CVSS 8.1
CVE-2025-71359 affects picklescan versions prior to 0.0.29, which fail to detect malicious pickle payloads utilizing lib2to3.pgen2.grammar.Grammar.loads in the …
CVE-2025-71360 CVSS 8.1
CVE-2025-71360 is a high-severity deserialization vulnerability in picklescan versions prior to 0.0.29, classified under CWE-502. The flaw stems from the idleli…
CVE-2025-71362 CVSS 8.1
CVE-2025-71362 is a high-severity deserialization vulnerability in picklescan versions prior to 0.0.33. The flaw allows attackers to execute arbitrary code via …
CVE-2025-71365 CVSS 8.1
CVE-2025-71365 is a high-severity vulnerability in picklescan versions prior to 0.0.33, classified under CWE-502 (Deserialization of Untrusted Data). The flaw a…
CVE-2025-71366 CVSS 8.1
picklescan versions prior to 0.0.28 fail to detect malicious function calls within pickle files, specifically those involving torch.utils.bottleneck.__main__.ru…
CVE-2025-71367 CVSS 8.1
Picklescan versions prior to 0.0.34 fail to detect _operator.attrgetter function calls within pickle payloads, allowing attackers to bypass security checks. Thi…
CVE-2025-71369 CVSS 8.1
CVE-2025-71369 affects picklescan versions prior to 0.0.28, which fail to detect malicious pickle files utilizing torch.utils.data.datapipes.utils.decoder.basic…
CVE-2025-71370 CVSS 8.1
CVE-2025-71370 is a high-severity vulnerability in picklescan versions prior to 0.0.28, classified under CWE-502 (Deserialization of Untrusted Data). The flaw a…
CVE-2025-71372 CVSS 8.1
Picklescan versions prior to 0.0.33 fail to detect the numpy.f2py.crackfortran.getlincoef gadget within pickle __reduce__ methods, resulting in a deserializatio…
CVE-2025-71373 CVSS 8.1
CVE-2025-71373 affects picklescan versions prior to 0.0.33, which fail to detect operator.methodcaller function calls within pickle files. This vulnerability cl…
CVE-2025-71375 CVSS 8.1
Picklescan versions prior to 0.0.34 fail to detect the _operator.methodcaller built-in function during pickle file analysis, allowing malicious payloads to evad…
CVE-2025-71376 CVSS 8.1
CVE-2025-71376 is a high-severity deserialization vulnerability in picklescan versions prior to 0.0.29. The flaw stems from CWE-502, as the tool fails to detect…
CVE-2025-71378 CVSS 8.1
CVE-2025-71378 affects picklescan versions prior to 0.0.30, which fail to detect cProfile.runctx function calls within pickle file reduce methods. This vulnerab…

Articles tagged with this vendor

No articles tagged with this vendor yet.