VDB

CVE-2021-34141

CVE-2021-34141 PUBLISHED

An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

EPSS 0.06% · 20.3th percentile

Risk Scores

EPSS Score
0.06%
20.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSnumpy*, 0, 1:1.19.5-1ubuntu2
Ubuntu:20.04:LTSnumpy1:1.17.3-0ubuntu2, 1:1.17.4-3ubuntu1, 1:1.17.4-3ubuntu2

Exploit Intelligence

Timeline

  • Dec 17, 2021 CVE Published
  • Dec 20, 2021 EPSS Score
  • Feb 12, 2022 EPSS Score
  • Apr 7, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Jul 26, 2022 EPSS Score
  • Sep 18, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 4, 2023 EPSS Score
  • Feb 24, 2023 CVE Updated
  • Feb 27, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›