Back to Database
Status published
High
CVE-2017-12852
The numpy.pad function in Numpy 1.13.1 and older versions is...
Vulnerability Description
The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-12852
Credits & Attribution
No credits recorded in the NVD database.
References
More from numpy
View All →CVE-2021-41496
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy...
Medium
5.5
CVE-2021-41495
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy <...
Medium
5.3
CVE-2021-34141
An incomplete string comparison in the numpy.core component in NumPy...
Medium
5.3
CVE-2021-33430
A Buffer Overflow vulnerability exists in NumPy 1.9.x in the...
Medium
5.3
CVE-2019-6446
An issue was discovered in NumPy before 1.16.3. It uses...
Critical
9.8
Affected Vendor
numpy
View all reports →Affected Software
numpy
Vulnerable Versions:
0
Timeline
Official Publish:
August 15th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.