CVE Feed

    Dashboard / CVE / CVE-2021-34141

    CVE-2021-34141

    An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."

    Published:May 11, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 17, 2021
    EPSS Score:0.00065
    CVSS Score:5.3

    Affected Products

    Vendor
    Numpy
    Product
    Numpy
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Policy

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High