CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-42702 Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized informati... Low inkscape 完成修复 2022-05-18 2026-03-26
CVE-2021-42700 Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information. Low inkscape 完成修复 2022-05-18 2026-03-27
CVE-2022-29162 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc pri... Low container-tools:2.0, container-tools:an8, container-tools:3.0, container-tools:4.0, container-tools:1.0, runc, udica 完成修复 2022-05-17 2026-07-09
CVE-2022-30767 nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed len... Moderate uboot-tools 完成修复 2022-05-16 2026-03-26
CVE-2022-1679 Linux内核的Atheros无线适配器驱动程序中发现了一个释放后使用缺陷,用户会强制ath9k_htc_wait_for_tar... Moderate kernel 完成修复 2022-05-16 2025-12-23
CVE-2021-45402 The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while... Moderate kernel:5.10, kernel:4.19, kernel(ANCK)4.19, kernel:6.6 完成修复 2022-05-16 2025-12-23
CVE-2021-4204 An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw a... Important kernel:4.19, kernel:4.18, kernel, kernel:6.6, kernel:5.10 完成修复 2022-05-16 2025-12-04
CVE-2021-33200 kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-b... Important kernel:5.10, kernel:4.19, kernel(ANCK)4.19, kernel:6.6 完成修复 2022-05-16 2025-12-04
CVE-2021-23133 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from ... Important kernel:5.10, kernel:4.19, kernel(ANCK)4.19, kernel:6.6 完成修复 2022-05-16 2025-12-04
CVE-2021-22600 A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to e... Important kernel:5.10, kernel:4.19, kernel(ANCK)4.19, kernel:6.6 完成修复 2022-05-16 2025-12-04
CVE-2020-26147 An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even thoug... Moderate kernel:5.10, kernel:4.19, kernel(ANCK)4.19, kernel:6.6 完成修复 2022-05-16 2025-12-23
CVE-2022-30775 xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafte... Moderate xpdf 完成修复 2022-05-15 2026-03-26
CVE-2022-1720 Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of cr... Moderate vim 完成修复 2022-05-13 2026-03-26
CVE-2022-25762 If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat... Low tomcat, pki-core:10.6 完成修复 2022-05-12 2026-03-26
CVE-2022-20117 In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could... Moderate kernel 完成修复 2022-05-10 2025-12-23
CVE-2022-1734 A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read... Important kernel:4.19, kernel(ANCK)5.10, kernel:6.6, kernel:5.10, kernel(ANCK)4.19 完成修复 2022-05-10 2025-12-05
CVE-2022-1652 Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw ... Important kernel:5.10, kernel:4.19, kernel(ANCK)5.10, kernel:6.6 完成修复 2022-05-10 2025-12-05
CVE-2022-30524 There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles... Important xpdf 完成修复 2022-05-09 2026-01-04
CVE-2022-28738 A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create ... Important ruby, ruby:3.0 完成修复 2022-05-09 2026-01-04
CVE-2022-1619 Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities... Important vim 完成修复 2022-05-08 2026-01-06
CVE-2022-30293 In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContents... Moderate webkit2gtk3 完成修复 2022-05-06 2026-07-13
CVE-2022-29167 Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic ve... Moderate firefox 完成修复 2022-05-06 2026-01-24
CVE-2022-25324 All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying th... Important perl-bignum 完成修复 2022-05-06 2026-01-05
CVE-2022-27337 A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafte... Moderate poppler 完成修复 2022-05-05 2026-07-10
CVE-2022-22368 IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to dec... Moderate kernel 完成修复 2022-05-03 2025-12-23
CVE-2022-1434 The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key ... Moderate openssl 完成修复 2022-05-03 2026-03-27
CVE-2022-1292 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by... Moderate openssl, mysql 完成修复 2022-05-03 2026-03-26
CVE-2021-41959 JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-re... Important git 完成修复 2022-05-03 2026-01-06
CVE-2022-29970 Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Important pcs 完成修复 2022-05-02 2026-01-05
CVE-2022-1012 A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb si... Important kernel:4.19, kernel(RHCK)4.18, kernel(ANCK)5.10, kernel:4.18, kernel:6.6, kernel:5.10, kernel(ANCK)4.19 完成修复 2022-05-02 2025-12-04
CVE-2021-46790 ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is t... Moderate sgabios 完成修复 2022-05-02 2026-06-26
CVE-2021-46662 MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nest... Moderate mariadb, mariadb:10.3, mariadb:10.5 完成修复 2022-04-29 2026-03-27
CVE-2018-25032 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. Important mingw-zlib, rsync, zlib 完成修复 2022-04-29 2026-01-10
CVE-2022-1271 An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen fil... Important xz, xz-java, gzip 完成修复 2022-04-28 2025-12-13
CVE-2022-1154 Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. Important vim 完成修复 2022-04-28 2026-01-06
CVE-2022-27239 In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to l... Important cifs-utils 完成修复 2022-04-27 2026-01-08
CVE-2022-24736 Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a speci... Low redis 完成修复 2022-04-27 2026-03-26
CVE-2022-24735 Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an atta... Low redis 完成修复 2022-04-27 2026-03-26
CVE-2022-24881 Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attacker... Critical freerdp 完成修复 2022-04-26 2026-01-10
CVE-2021-41041 In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when ver... Moderate eclipse 完成修复 2022-04-26 2026-07-12
CVE-2022-28506 There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45 Moderate giflib 完成修复 2022-04-25 2026-07-13
CVE-2022-27406 FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT... Moderate freetype 完成修复 2022-04-22 2026-03-26
CVE-2022-27405 FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FN... Moderate freetype 完成修复 2022-04-22 2026-03-26
CVE-2022-27404 FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt... Moderate freetype 完成修复 2022-04-22 2026-03-26
CVE-2022-24883 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication again... Moderate freerdp 完成修复 2022-04-22 2026-07-11
CVE-2022-24882 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authen... Important freerdp 完成修复 2022-04-22 2026-01-07
CVE-2022-21451 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 ... Moderate mariadb, mysql, mysql:8.0 完成修复 2022-04-20 2026-03-26
CVE-2022-24826 On Windows, if Git LFS operates on a malicious repository with a ..exe file as well as a file named git.exe, and git.exe ... Important git 完成修复 2022-04-19 2025-12-13
CVE-2022-21490 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21489 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21486 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Low mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21485 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Low mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21484 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Low mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21483 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-21482 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2022-04-19 2026-03-26
CVE-2022-0070 Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now... Important kernel 完成修复 2022-04-19 2025-12-04
CVE-2021-39078 IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Forc... Moderate kernel 完成修复 2022-04-19 2026-01-22
CVE-2021-39076 IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... Important kernel 完成修复 2022-04-19 2025-12-04
CVE-2021-3100 The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be... Important kernel 完成修复 2022-04-19 2025-12-04
CVE-2021-42782 Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs... Moderate openscap, opensc 完成修复 2022-04-18 2026-03-26
CVE-2021-42780 A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs... Moderate openscap, opensc 完成修复 2022-04-18 2026-03-26
CVE-2021-42778 A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. Moderate openscap, opensc 完成修复 2022-04-18 2026-03-26
CVE-2021-3681 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that... Important ansible-core 完成修复 2022-04-18 2026-01-06
CVE-2020-15778 DISPUTED scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtic... Important openssh, openSSH 完成修复 2022-04-18 2026-01-09
CVE-2011-4917 In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat. Moderate kernel 完成修复 2022-04-18 2025-12-23
CVE-2022-27457 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype... Important mariadb:10.5, mariadb 完成修复 2022-04-14 2026-01-04
CVE-2022-27455 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/... Important mariadb:10.5, mariadb 完成修复 2022-04-14 2026-01-04
CVE-2022-27451 MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc. Important mariadb:10.5, mariadb 完成修复 2022-04-14 2026-01-04
CVE-2022-27446 MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h. Important mariadb:10.5, mariadb 完成修复 2022-04-14 2026-01-04
CVE-2022-27444 MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc. Important mariadb:10.5, mariadb 完成修复 2022-04-14 2026-01-04
CVE-2022-1328 Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input li... Moderate mutt 完成修复 2022-04-14 2026-07-10
CVE-2022-1304 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly ... Important e2fsprogs 完成修复 2022-04-14 2026-01-09
CVE-2022-25648 The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = '... Critical git-lfs, git 完成修复 2022-04-13 2026-01-09
CVE-2022-28347 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4... Important python-django 完成修复 2022-04-12 2026-01-04
CVE-2022-28346 An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(),... Important python-django 完成修复 2022-04-12 2026-01-04
CVE-2022-27385 An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was d... Moderate mariadb 完成修复 2022-04-12 2026-06-24
CVE-2022-27382 MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Itemfield::used_tables/update... Important mariadb:10.5, mariadb 完成修复 2022-04-12 2026-01-04
CVE-2022-24765 Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user ma... Moderate git 完成修复 2022-04-12 2026-03-25
CVE-2022-24838 Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newl... Critical ocaml-calendar 完成修复 2022-04-11 2026-01-10
CVE-2022-24829 Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did no... Critical kubernetes 完成修复 2022-04-11 2026-01-10
CVE-2022-22964 VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due... Important kernel 完成修复 2022-04-11 2025-12-04
CVE-2022-22962 VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default sh... Important kernel 完成修复 2022-04-11 2025-12-04
CVE-2022-29582 In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be... Important kernel:4.19, kernel:6.6, kernel:5.10 完成修复 2022-04-08 2025-12-04
CVE-2021-43138 In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal... Moderate firefox 完成修复 2022-04-07 2026-01-24
CVE-2022-26635 PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Moderate memcached 完成修复 2022-04-05 2026-03-25
CVE-2022-24795 yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of yajl contain a... Moderate yajl 完成修复 2022-04-05 2026-03-25
CVE-2021-38834 easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special... Important easymock 完成修复 2022-04-05 2026-01-08
CVE-2022-28390 ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. Important kernel:4.19, kernel(ANCK)4.19, kernel:5.10, kernel 完成修复 2022-04-04 2025-12-04
CVE-2022-24785 Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerabil... Important container-tools:4.0, cockpit-composer, grafana, container-tools:2.0, cockpit-appstream, nodejs:18, container-tools:3.0, cockpit, container-tools:an8, cockpit-session-recording, grafana-pcp 完成修复 2022-04-04 2025-12-29
CVE-2021-33657 There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a ... Important SDL2 完成修复 2022-04-01 2026-01-04
CVE-2022-21821 NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacke... Important kernel 完成修复 2022-03-29 2025-12-08
CVE-2022-1122 A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number... Low openjpeg2 完成修复 2022-03-29 2026-03-27
CVE-2021-28544 Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidde... Moderate subversion 完成修复 2022-03-27 2026-01-25
CVE-2022-24778 The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder... Important containerd 完成修复 2022-03-25 2026-01-04
CVE-2022-0897 A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfi... Low sgabios 完成修复 2022-03-25 2025-12-18
CVE-2021-3933 An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an in... Moderate OpenEXR 完成修复 2022-03-25 2026-03-25
CVE-2021-20290 An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to... Moderate openscap 完成修复 2022-03-25 2026-03-25
CVE-2022-1048 A use-after-free flaw was found in the Linux kernel?s sound subsystem in the way a user triggers concurrent calls of PCM hw_par... Important kernel:4.19, kernel:6.6, kernel(ANCK)4.19, kernel:5.10 完成修复 2022-03-23 2025-12-04
CVE-2021-25220 BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 ->... Moderate bind9.16, bind, sssd 完成修复 2022-03-23 2026-03-25
CVE-2022-0318 Heap-based Buffer Overflow in vim/vim prior to 8.2. Moderate vim 完成修复 2022-03-22 2026-03-25

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""