Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101681
HistoryDec 21, 2021 - 12:00 a.m.

NumPy has an unspecified vulnerability

2021-12-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
12

0.001 Low

EPSS

Percentile

31.9%

NumPy is a Python scientific computing package. The product supports a large number of dimensional arrays and matrices, while providing a large library of mathematical functions for data operations. numPy 1.19 has a security vulnerability that stems from a null pointer dereference vulnerability in numpy. In the software PyArray_DescrNew function, the lack of return value validation leads to a null pointer dereference vulnerability, which can be exploited by attackers to conduct DoS attacks by repeatedly creating sorted arrays.

CPENameOperatorVersion
numpy numpyle1.19.0