CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2022-24773 Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, ... Moderate dotnet3.1 完成修复 2022-03-18 2025-12-05
CVE-2022-24772 Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, ... Moderate dotnet3.1 完成修复 2022-03-18 2025-12-05
CVE-2022-24771 Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, ... Moderate dotnet3.1 完成修复 2022-03-18 2025-12-05
CVE-2022-23852 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT... Moderate expat 完成修复 2022-03-17 2026-01-25
CVE-2022-23308 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. Important libxml2 完成修复 2022-03-17 2026-01-09
CVE-2022-22827 storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-22826 nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-22825 lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-22824 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-22823 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-22822 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Important expat 完成修复 2022-03-17 2026-01-09
CVE-2022-1049 A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with exp... Moderate pcs 完成修复 2022-03-17 2026-07-09
CVE-2021-23632 All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, wh... Critical git 完成修复 2022-03-17 2025-12-29
CVE-2022-0358 A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to C... Important virt:an, qemu, libvirt-glib 完成修复 2022-03-16 2025-12-09
CVE-2021-39711 In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to ... Low kernel 完成修复 2022-03-16 2026-01-23
CVE-2021-23648 The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in s... Moderate grafana 完成修复 2022-03-16 2026-07-13
CVE-2021-39275 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to ... Important httpd:2.4, httpd 完成修复 2022-03-15 2026-01-09
CVE-2021-34798 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier... Important httpd:2.4, httpd 完成修复 2022-03-15 2026-01-09
CVE-2022-23943 Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly at... Moderate httpd 完成修复 2022-03-14 2026-07-11
CVE-2022-22721 If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow ... Moderate httpd 完成修复 2022-03-14 2026-07-11
CVE-2022-22719 A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue af... Moderate httpd 完成修复 2022-03-14 2026-07-11
CVE-2022-26981 Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/l... Important liblouis 完成修复 2022-03-13 2026-01-06
CVE-2022-25315 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. Important cmake, expat, thunderbird, firefox, mingw-expat 完成修复 2022-03-11 2026-01-04
CVE-2022-25236 xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. Important firefox, expat, mingw-expat, thunderbird 完成修复 2022-03-11 2026-01-09
CVE-2022-25235 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 cha... Important xmlrpc-c, expat, thunderbird, firefox, mingw-expat 完成修复 2022-03-11 2026-01-08
CVE-2022-0924 Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For ... Moderate libtiff 完成修复 2022-03-11 2026-03-25
CVE-2022-0891 A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigge... Low libtiff 完成修复 2022-03-10 2026-03-25
CVE-2022-0865 Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users... Moderate libtiff 完成修复 2022-03-10 2026-03-25
CVE-2021-44269 An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples... Low wavpack 完成修复 2022-03-10 2026-03-25
CVE-2021-28488 Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access availab... Moderate NetworkManager 完成修复 2022-03-10 2026-03-25
CVE-2021-39715 In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This co... Moderate kernel 完成修复 2022-03-07 2025-12-23
CVE-2022-24921 regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. Moderate golang, go-toolset:an8 完成修复 2022-03-05 2025-12-17
CVE-2022-26126 Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary str... Moderate frr 完成修复 2022-03-03 2026-07-10
CVE-2022-24724 cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28... Important pandoc 完成修复 2022-03-03 2026-01-05
CVE-2022-24723 URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of... Moderate dotnet3.1 完成修复 2022-03-03 2025-12-05
CVE-2022-21716 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and ... Important python-twisted 完成修复 2022-03-03 2026-01-04
CVE-2021-38578 Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. Important edk2 完成修复 2022-03-03 2026-01-08
CVE-2021-3602 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in cont... Moderate toolbox, container-tools:4.0, buildah, container-tools:2.0, podman, container-tools:3.0, container-tools:an8, container-tools:1.0, udica 完成修复 2022-03-03 2026-06-26
CVE-2022-0711 A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an atta... Important haproxy 完成修复 2022-03-02 2026-01-05
CVE-2021-40438 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issu... Important httpd:2.4, httpd 完成修复 2022-03-02 2026-01-09
CVE-2021-3667 An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupB... Low libvirt 完成修复 2022-03-02 2025-12-18
CVE-2021-3654 A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirec... Moderate python 完成修复 2022-03-02 2026-03-25
CVE-2021-3631 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploit... Low libvirt 完成修复 2022-03-02 2025-12-18
CVE-2021-3623 A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and... Moderate libtpms 完成修复 2022-03-02 2026-03-25
CVE-2021-38201 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab... Important kernel:4.19, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:5.10 完成修复 2022-02-28 2025-12-04
CVE-2021-21708 In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE... Moderate php-pear, php 完成修复 2022-02-27 2026-03-25
CVE-2022-24407 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statem... Important cyrus-sasl 完成修复 2022-02-24 2026-01-06
CVE-2022-21824 Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to th... Low nodejs:16, nodejs-nodemon 完成修复 2022-02-24 2026-07-10
CVE-2021-44533 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attack... Moderate nodejs:16, nodejs-nodemon 完成修复 2022-02-24 2026-06-25
CVE-2021-44532 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses thi... Moderate nodejs, nodejs:12 完成修复 2022-02-24 2026-03-25
CVE-2021-44531 Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, ca... Moderate nodejs:16, nodejs-nodemon 完成修复 2022-02-24 2026-07-10
CVE-2021-3752 A use-after-free flaw was found in the Linux kernel&#8217;s Bluetooth subsystem in the way user calls connect to the socket... Important kernel:4.19, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:5.10 完成修复 2022-02-24 2025-12-04
CVE-2022-22817 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec met... Important python-pillow 完成修复 2022-02-23 2026-01-04
CVE-2022-22816 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. Moderate python-pillow 完成修复 2022-02-23 2026-03-25
CVE-2021-25636 CVE-2021-25636 Title: Incorrect trust validation of signature with ambiguous KeyInfo children Announced: February 22, 202... Moderate libreoffice 完成修复 2022-02-22 2026-07-11
CVE-2021-45083 An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sens... Moderate cobbler 完成修复 2022-02-20 2026-07-11
CVE-2022-24052 MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local a... Important mariadb 完成修复 2022-02-18 2026-01-04
CVE-2022-24051 MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to e... Important mariadb 完成修复 2022-02-18 2026-01-04
CVE-2022-24050 MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to ... Important mariadb 完成修复 2022-02-18 2026-01-04
CVE-2022-24048 MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local ... Important mariadb 完成修复 2022-02-18 2026-01-04
CVE-2022-23645 swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, ... Low sgabios 完成修复 2022-02-18 2026-07-10
CVE-2021-45082 An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheet... Moderate cobbler 完成修复 2022-02-18 2026-07-13
CVE-2021-45081 An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HT... Low cobbler 完成修复 2022-02-18 2026-07-09
CVE-2021-41819 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3... Important ruby:3.3, ruby:2.6, ruby:3.0, ruby, ruby:2.7, ruby:2.5 完成修复 2022-02-18 2026-01-04
CVE-2021-41817 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fi... Important ruby:2.6, ruby:3.0, ruby, ruby:2.7, ruby:2.5 完成修复 2022-02-18 2026-01-04
CVE-2021-20325 Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, cau... Important httpd 完成修复 2022-02-18 2026-01-09
CVE-2016-20013 sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's ... Important libxcrypt 完成修复 2022-02-18 2025-12-29
CVE-2022-25265 In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2... Important kernel, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2022-02-16 2025-12-04
CVE-2022-0613 Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. Moderate dotnet3.1, dotnet5.0 完成修复 2022-02-16 2025-12-05
CVE-2021-3781 A trivial sandbox (enabled with the -dSAFER option) escape flaw was found in the ghostscript interpreter by injecting a speci... Important ghostscript 完成修复 2022-02-16 2026-01-07
CVE-2022-23639 crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent programming in... Important librsvg2, thunderbird, firefox, mozjs52, rust 完成修复 2022-02-15 2026-01-04
CVE-2022-0582 Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via p... Moderate wireshark 完成修复 2022-02-14 2026-01-25
CVE-2022-23634 Puma is a Ruby/Rack web server built for parallelism. Prior to puma version 5.6.2, puma may not always call close on th... Important libdb 完成修复 2022-02-11 2026-01-08
CVE-2021-33155 Improper input validation in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-33139 Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-33120 Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow a... Moderate microcode_ctl 完成修复 2022-02-09 2026-03-25
CVE-2021-33115 Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enabl... Important linux-firmware 完成修复 2022-02-09 2026-01-05
CVE-2021-33114 Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 1... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-33113 Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 1... Important linux-firmware 完成修复 2022-02-09 2026-01-05
CVE-2021-33110 Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 a... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-33061 Insufficient control flow management for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user t... Moderate kernel 4.19, kernel(ANCK)5.10 完成修复 2022-02-09 2025-12-23
CVE-2021-0183 Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi in mul... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0176 Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM)... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0175 Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in mul... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0174 Improper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0173 Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating syste... Moderate linux-firmware 完成修复 2022-02-09 2026-07-11
CVE-2021-0172 Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM)... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0170 Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple oper... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0168 Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM)... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0166 Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple oper... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0165 Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in ... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0164 Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Wi... Important linux-firmware 完成修复 2022-02-09 2026-01-05
CVE-2021-0161 Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in ... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0145 Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable i... Moderate microcode_ctl 完成修复 2022-02-09 2026-07-10
CVE-2021-0076 Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in mul... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0072 Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM)... Moderate linux-firmware 完成修复 2022-02-09 2026-03-25
CVE-2021-0066 Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in ... Important linux-firmware 完成修复 2022-02-09 2026-01-05
CVE-2020-9492 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorizati... Important lucene 完成修复 2022-02-09 2026-01-05
CVE-2022-21713 Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints... Moderate grafana, grafana-pcp 完成修复 2022-02-08 2026-03-27
CVE-2022-21703 Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forg... Moderate grafana 完成修复 2022-02-08 2026-03-27

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""