| CVE-2022-22752 |
Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2022-22736 |
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default. *This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2022-21797 |
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. |
Critical |
python-joblib |
否 |
完成修复 |
2024-11-24 |
2026-01-09 |
| CVE-2022-21699 |
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade. |
Important |
ipython |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2022-2120 |
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution. |
Critical |
dcmtk |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2022-2119 |
OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution. |
Critical |
dcmtk |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2022-1920 |
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite. |
Important |
gstreamer1-plugins-good |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2022-1887 |
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101. |
Critical |
firefox |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2022-0843 |
Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2022-0511 |
Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-42386 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-42384 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-42383 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-42382 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-42379 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-42378 |
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function |
Important |
busybox |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-40226 |
xpdfreader 4.03 is vulnerable to Buffer Overflow. |
Important |
poppler |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2021-38499 |
Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-38494 |
Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-38094 |
Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-38093 |
Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-38092 |
Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-38091 |
Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-38090 |
Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-3682 |
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host. |
Important |
qemu, qemu-kvm |
否 |
完成修复 |
2024-11-24 |
2025-12-10 |
| CVE-2021-36493 |
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. |
Important |
xpdf |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2021-36090 |
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. |
Important |
apache-commons-compress |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-35517 |
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. |
Important |
apache-commons-compress |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-35516 |
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. |
Important |
apache-commons-compress |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-35515 |
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. |
Important |
apache-commons-compress |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-3500 |
A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences. |
Important |
djvulibre |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-34432 |
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. |
Important |
mosquitto |
否 |
完成修复 |
2024-11-24 |
2026-01-08 |
| CVE-2021-33815 |
dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-32797 |
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html ` |
Critical |
jupyterlab |
否 |
完成修复 |
2024-11-24 |
2026-01-10 |
| CVE-2021-32492 |
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences. |
Important |
djvulibre |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-31598 |
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap-based buffer overflow. |
Important |
netcdf |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-30123 |
FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2021-29993 |
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29990 |
Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 91. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29977 |
Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 90. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29973 |
Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29972 |
A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29968 |
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29966 |
Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 89. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29947 |
Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-29472 |
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercurial is installed on the system. The impact to Composer users directly is limited as the composer.json file is typically under their own control and source download URLs can only be supplied by third party Composer repositories they explicitly trust to download and execute source code from, e.g. Composer plugins. The main impact is to services passing user input to Composer, including Packagist.org and Private Packagist. This allowed users to trigger remote code execution. The vulnerability has been patched on Packagist.org and Private Packagist within 12h of receiving the initial vulnerability report and based on a review of logs, to the best of our knowledge, was not abused by anyone. Other services/tools using VcsRepository/VcsDriver or derivatives may also be vulnerable and should upgrade their composer/composer dependency immediately. Versions 1.10.22 and 2.0.13 include patches for this issue. |
Important |
composer |
否 |
完成修复 |
2024-11-24 |
2026-01-07 |
| CVE-2021-29468 |
Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that contains symbolic links as well as files with backslash characters in the file name may cause just-checked out code to be executed while checking out a repository using Git on Cygwin. The problem will be patched in the Cygwin Git v2.31.1-2 release. At time of writing, the vulnerability is present in the upstream Git source code; any Cygwin user who compiles Git for themselves from upstream sources should manually apply a patch to mitigate the vulnerability. As mitigation users should not clone or pull from repositories from untrusted sources. CVE-2019-1354 was an equivalent vulnerability in Git for Visual Studio. |
Important |
git |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2021-28302 |
A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash. |
Important |
libupnp |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2021-28026 |
jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service. |
Important |
jpegxl |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-27804 |
JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption. |
Critical |
jpegxl |
否 |
完成修复 |
2024-11-24 |
2026-01-10 |
| CVE-2021-27138 |
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT |
Important |
uboot-tools |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-27097 |
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. |
Important |
uboot-tools |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-25741 |
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. |
Important |
kubernetes |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2021-25122 |
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request. |
Important |
tomcat |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2021-24028 |
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00. |
Critical |
thrift |
否 |
完成修复 |
2024-11-24 |
2026-01-07 |
| CVE-2021-23997 |
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-23988 |
Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-23972 |
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-23965 |
Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-30 |
| CVE-2021-23962 |
Incorrect use of the '' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2021-23957 |
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2020-8558 |
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service. |
Important |
kubernetes |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-6817 |
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}). |
Important |
python-bleach |
否 |
完成修复 |
2024-11-24 |
2026-01-04 |
| CVE-2020-36430 |
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction. |
Important |
libass |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-36152 |
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA. |
Important |
libmysofa |
否 |
完成修复 |
2024-11-24 |
2026-01-05 |
| CVE-2020-36133 |
AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. |
Important |
aom |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-36131 |
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c. |
Important |
aom |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-36129 |
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c. |
Important |
aom |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-35114 |
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84. |
Important |
firefox |
否 |
完成修复 |
2024-11-24 |
2025-12-29 |
| CVE-2020-27637 |
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3 |
Critical |
R |
否 |
完成修复 |
2024-11-24 |
2026-01-07 |
| CVE-2020-26797 |
Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping. |
Important |
libmediainfo |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-24995 |
Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local). |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-24994 |
Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file. |
Important |
libass |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2020-24020 |
Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22036 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22035 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22034 |
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22032 |
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22031 |
A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22030 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22029 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22027 |
A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22025 |
A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22023 |
A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22022 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22017 |
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22016 |
A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-22015 |
Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-21688 |
A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-21041 |
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20898 |
Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20896 |
An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20892 |
An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20891 |
Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20451 |
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-20450 |
FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service. |
Important |
ffmpeg |
否 |
完成修复 |
2024-11-24 |
2025-12-06 |
| CVE-2020-18771 |
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak. |
Important |
exiv2 |
否 |
完成修复 |
2024-11-24 |
2026-01-07 |
| CVE-2019-25059 |
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839. |
Important |
ghostscript |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |
| CVE-2019-11245 |
In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the container as root. If the pod did not specify mustRunAsNonRoot: true, the kubelet will run the container as uid 0. |
Important |
kubernetes |
否 |
完成修复 |
2024-11-24 |
2026-01-06 |