CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2022-33105 Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID. Important redis 完成修复 2022-06-23 2026-01-04
CVE-2022-33070 Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/p... Moderate protobuf-c 完成修复 2022-06-23 2026-07-10
CVE-2022-28737 There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() f... Moderate shim, grub2, shim-unsigned-aarch64, shim-unsigned-x64, mokutil 完成修复 2022-06-23 2026-07-09
CVE-2022-2183 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Low vim 完成修复 2022-06-23 2026-03-26
CVE-2022-2182 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Low vim 完成修复 2022-06-23 2026-03-26
CVE-2022-2175 Buffer Over-read in GitHub repository vim/vim prior to 8.2. Important vim 完成修复 2022-06-23 2026-01-05
CVE-2022-2068 In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash scrip... Moderate openssl 完成修复 2022-06-21 2026-03-27
CVE-2022-2129 Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. Moderate vim 完成修复 2022-06-19 2026-03-26
CVE-2022-2126 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Low vim 完成修复 2022-06-19 2026-03-26
CVE-2022-2125 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Important vim 完成修复 2022-06-19 2026-01-05
CVE-2022-2124 Buffer Over-read in GitHub repository vim/vim prior to 8.2. Low vim 完成修复 2022-06-19 2026-03-26
CVE-2022-32276 DISPUTED Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the ven... Important grafana 完成修复 2022-06-17 2026-01-04
CVE-2022-26691 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Mon... Important cups 完成修复 2022-06-17 2026-01-07
CVE-2022-25345 All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with z... Important opus 完成修复 2022-06-17 2026-01-05
CVE-2022-23806 Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with... Moderate golang, go-toolset:an8 完成修复 2022-06-15 2025-12-17
CVE-2022-23772 Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Co... Important golang, go-toolset:an8 完成修复 2022-06-15 2025-12-17
CVE-2022-20162 In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to ... Low runc 完成修复 2022-06-15 2026-07-10
CVE-2022-20141 In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation o... Important kernel:4.19, kernel:4.18, kernel, kernel:6.6, kernel:5.10 完成修复 2022-06-15 2025-12-05
CVE-2022-1552 A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaini... Important postgresql:13, postgresql, postgresql:10, postgresql:12 完成修复 2022-06-15 2026-01-04
CVE-2021-45930 Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath... Important qt5-qtsvg 完成修复 2022-06-15 2026-01-04
CVE-2021-44733 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because ... Important kernel:4.19, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:5.10 完成修复 2022-06-15 2025-12-05
CVE-2021-44224 A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, f... Important httpd:2.4, httpd 完成修复 2022-06-15 2026-01-09
CVE-2021-41771 ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location A... Important golang, go-toolset:an8 完成修复 2022-06-15 2025-12-17
CVE-2021-4158 A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use th... Moderate qemu, virt:an, qemu-kvm 完成修复 2022-06-15 2025-12-18
CVE-2021-4145 A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The self pointer is ... Moderate qemu, virt:an, qemu-kvm 完成修复 2022-06-15 2025-12-18
CVE-2021-41415 Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter. Moderate subscription-manager 完成修复 2022-06-15 2026-06-27
CVE-2021-39293 In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are ... Important golang, container-tools:2.0, buildah, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, go-toolset:an8 完成修复 2022-06-15 2025-12-17
CVE-2021-39263 A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, ... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39262 A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39261 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39260 A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39259 A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_nam... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39258 A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39256 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39255 A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39254 A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_att... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39253 A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39252 A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-39251 A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22. Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-38297 Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module... Moderate golang, git-lfs, container-tools:2.0, buildah, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, go-toolset:an8 完成修复 2022-06-15 2025-12-17
CVE-2021-38185 GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr ... Important cpio 完成修复 2022-06-15 2026-01-07
CVE-2021-3802 A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel pa... Moderate udisks2 完成修复 2022-06-15 2026-06-26
CVE-2021-3748 A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs... Important qemu, virt:an, qemu-kvm 完成修复 2022-06-15 2025-12-09
CVE-2021-3737 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, ... Moderate python27:2.7, python38:3.8, python3 完成修复 2022-06-15 2026-03-26
CVE-2021-3698 A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System... Important cockpit, cockpit-session-recording 完成修复 2022-06-15 2026-01-08
CVE-2021-3660 Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit se... Moderate cockpit, cockpit-session-recording 完成修复 2022-06-15 2026-03-27
CVE-2021-3622 A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, ... Moderate virt:an, hivex 完成修复 2022-06-15 2026-06-26
CVE-2021-36160 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue a... Important httpd:2.4, httpd 完成修复 2022-06-15 2026-01-09
CVE-2021-3612 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in th... Important kernel:4.19, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:5.10 完成修复 2022-06-15 2025-12-05
CVE-2021-35269 NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_fla... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-35268 In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buf... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-35267 NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing f... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-35266 In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overfl... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-33289 In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can o... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-33287 In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buff... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-33286 In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow ca... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-33285 In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, ... Important virt:an, ntfs-3g 完成修复 2022-06-15 2025-12-30
CVE-2021-33193 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting ... Important httpd:2.4, httpd 完成修复 2022-06-15 2026-01-09
CVE-2020-35492 A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a ... Important pixman, cairo 完成修复 2022-06-15 2026-01-04
CVE-2020-35452 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. The... Important httpd:2.4, httpd 完成修复 2022-06-15 2026-01-09
CVE-2020-27820 A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing de... Moderate kernel:4.19, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:5.10 完成修复 2022-06-15 2025-12-23
CVE-2020-17489 An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the pass... Moderate gnome-shell 完成修复 2022-06-15 2026-03-26
CVE-2022-21504 The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allo... Moderate kernel 完成修复 2022-06-14 2025-12-23
CVE-2022-21127 Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to... Moderate microcode_ctl 完成修复 2022-06-14 2026-03-26
CVE-2022-1976 A flaw was found in the Linux kernels implementation of IO-URING. An attacker with a local executable permission can create a... Moderate kernel 完成修复 2022-06-14 2025-12-23
CVE-2021-40633 A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exc... Important giflib 完成修复 2022-06-14 2026-01-06
CVE-2022-29244 npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace fla... Important nodejs-packaging, nodejs 完成修复 2022-06-13 2026-01-05
CVE-2022-32981 An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PE... Important kernel:5.10, kernel:4.19, kernel, kernel:6.6 完成修复 2022-06-10 2025-12-05
CVE-2022-30610 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page link... Moderate kernel 完成修复 2022-06-10 2025-12-23
CVE-2022-21211 This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the value of t... Important lua-posix 完成修复 2022-06-10 2026-01-04
CVE-2022-31813 Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connecti... Moderate httpd 完成修复 2022-06-09 2026-07-11
CVE-2022-30522 If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be ver... Moderate httpd:2.4, httpd 完成修复 2022-06-09 2026-07-10
CVE-2022-29404 In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of s... Moderate httpd 完成修复 2022-06-09 2026-07-11
CVE-2022-26377 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server al... Moderate httpd 完成修复 2022-06-09 2026-07-11
CVE-2019-25067 A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the c... Moderate podman 完成修复 2022-06-09 2026-03-26
CVE-2022-32202 In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp. Moderate libjpeg 完成修复 2022-06-02 2026-03-26
CVE-2022-32201 In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp. Moderate libjpeg 完成修复 2022-06-02 2026-03-26
CVE-2022-31796 libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp b... Moderate libjpeg 完成修复 2022-06-02 2026-03-26
CVE-2022-31782 ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow. Important freetype 完成修复 2022-06-02 2026-01-07
CVE-2022-26491 An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection... Moderate pidgin 完成修复 2022-06-02 2026-01-25
CVE-2022-24903 Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when... Important rsyslog 完成修复 2022-06-01 2026-01-09
CVE-2022-30789 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22. Moderate sgabios, ntfs-3g 完成修复 2022-05-26 2026-03-27
CVE-2022-30788 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22. Moderate sgabios, ntfs-3g 完成修复 2022-05-26 2026-03-27
CVE-2022-30786 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22. Moderate virt:an, ntfs-3g 完成修复 2022-05-26 2026-03-26
CVE-2022-30784 A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22. Moderate sgabios, ntfs-3g 完成修复 2022-05-26 2026-03-26
CVE-2022-26720 An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-004 Catal... Important httpd 完成修复 2022-05-26 2026-01-09
CVE-2022-22662 A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalin... Moderate webkit2gtk3 完成修复 2022-05-26 2026-07-13
CVE-2022-1664 Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone t... Low dpkg 完成修复 2022-05-26 2026-01-25
CVE-2022-31624 MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method lo... Moderate mariadb 完成修复 2022-05-25 2026-06-24
CVE-2022-31621 MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (strea... Moderate mariadb 完成修复 2022-05-25 2026-06-24
CVE-2022-29361 DISPUTED Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request ... Critical python-werkzeug 完成修复 2022-05-24 2026-01-09
CVE-2022-1786 A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_I... Important kernel:5.10, kernel:4.19, kernel(ANCK)5.10, kernel:6.6 完成修复 2022-05-24 2025-12-04
CVE-2021-3597 A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a de... Moderate fuse 完成修复 2022-05-24 2026-07-10
CVE-2022-29170 Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows... Important grafana 完成修复 2022-05-20 2026-01-04
CVE-2022-28660 The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-... Critical grafana 完成修复 2022-05-20 2026-01-10
CVE-2022-28948 An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. Moderate yaml,golang-gopkg-yaml-3 完成修复 2022-05-19 2026-07-10
CVE-2022-30959 A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to ... Moderate openssh 完成修复 2022-05-18 2026-03-26
CVE-2022-30958 A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an att... Important openssh 完成修复 2022-05-18 2026-01-09
CVE-2022-30957 A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate c... Moderate openssh 完成修复 2022-05-18 2026-03-26
CVE-2021-42704 Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. Important inkscape 完成修复 2022-05-18 2026-01-06

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""