CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-44420 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypa... Important python-django 完成修复 2021-12-07 2026-01-04
CVE-2021-43784 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used in... Low container-tools:4.0, container-tools:2.0, runc, container-tools:3.0, container-tools:an8, container-tools:1.0 完成修复 2021-12-06 2026-07-09
CVE-2021-43565 There's an input validation flaw in golang.org/x/crypto's readCipherPacket() function. An unauthenticated attacker who sends an... Important docker, golang, go-toolset:an8 完成修复 2021-12-02 2025-12-17
CVE-2021-34599 Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git doe... Important git 完成修复 2021-12-01 2026-01-06
CVE-2021-38503 The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as exec... Important thunderbird, firefox 完成修复 2021-11-30 2026-01-04
CVE-2021-44201 Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 ... Moderate kernel 完成修复 2021-11-29 2025-12-17
CVE-2021-3656 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virt... Important kernel:4.19, kernel:4.18, kernel, kernel:6.6, kernel:5.10, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(RHCK)4.18 (Anolis OS 8.2), kernel(ANCK)4.19 完成修复 2021-11-26 2025-12-04
CVE-2021-3653 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virt... Important kernel:4.19, kernel:4.18, kernel:6.6, kernel:5.10, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(RHCK)4.18 (Anolis OS 8.2), kernel(ANCK)4.19 完成修复 2021-11-26 2025-12-04
CVE-2021-26615 ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function beca... Important kernel 完成修复 2021-11-26 2025-12-04
CVE-2021-32037 An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation requ... Moderate mongodb 完成修复 2021-11-24 2026-07-09
CVE-2021-43267 An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (T... Important kernel(RHCK)4.18 (Anolis OS 8.5), kernel, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(ANCK) 5.10 完成修复 2021-11-23 2025-12-04
CVE-2020-16156 CPAN 2.28 allows Signature Verification Bypass. Moderate perl-CPAN, perl, perl-any-uri-escape 完成修复 2021-11-23 2026-03-24
CVE-2021-23217 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated pri... Important kernel 完成修复 2021-11-20 2025-12-04
CVE-2021-33058 Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.... Important perl-version 完成修复 2021-11-17 2026-01-04
CVE-2021-42377 An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when proces... Moderate busybox 完成修复 2021-11-16 2026-03-24
CVE-2021-37580 A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authenti... Critical maven 完成修复 2021-11-16 2026-01-10
CVE-2021-43332 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admi... Moderate mailman 完成修复 2021-11-13 2026-07-10
CVE-2021-43331 In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. Moderate mailman 完成修复 2021-11-13 2026-07-10
CVE-2020-23903 A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of serv... Moderate speexdsp, speex 完成修复 2021-11-11 2026-03-24
CVE-2021-3572 A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use... Low python27:2.7, python-pip, python38:3.8 完成修复 2021-11-10 2026-03-24
CVE-2021-27645 The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for... Low glibc 完成修复 2021-11-09 2025-12-11
CVE-2021-3928 vim is vulnerable to Use of Uninitialized Variable Important vim 完成修复 2021-11-05 2026-01-04
CVE-2021-29991 Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header ... Important thunderbird 完成修复 2021-11-03 2026-01-05
CVE-2021-42697 Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allow... Important httpd 完成修复 2021-11-02 2026-01-09
CVE-2017-5123 Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. Important kernel 完成修复 2021-11-02 2025-12-04
CVE-2021-42694 An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adv... Moderate rust 完成修复 2021-11-01 2025-12-16
CVE-2021-41035 In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible i... Moderate java-11-openjdk 完成修复 2021-10-25 2025-12-05
CVE-2021-22923 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metali... Moderate curl (Anolis OS 8.2), curl (Anolis OS 8.4), curl 完成修复 2021-10-25 2026-03-24
CVE-2021-22922 When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the ... Moderate curl (Anolis OS 8.2), curl (Anolis OS 8.4), curl 完成修复 2021-10-25 2026-03-24
CVE-2020-27304 The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in... Important ceph 完成修复 2021-10-21 2026-01-08
CVE-2021-35621 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35619 Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, ... Important java-1.8.0-openjdk 完成修复 2021-10-20 2025-12-05
CVE-2021-35618 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Low mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35613 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Low mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35610 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected ... Important mariadb:10.5, mysql:8.0, mariadb, mysql 完成修复 2021-10-20 2026-01-04
CVE-2021-35598 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35594 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35593 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35592 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35590 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35584 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: ndbcluster/plugin DDL). Supported versions that... Moderate mysql 完成修复 2021-10-20 2026-03-24
CVE-2021-35560 Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java ... Important java-11-openjdk, icedtea-web, java-1.8.0-openjdk 完成修复 2021-10-20 2025-12-05
CVE-2021-35538 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is aff... Important kernel 完成修复 2021-10-20 2025-12-04
CVE-2021-3746 A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is trigge... Moderate libtpms 完成修复 2021-10-19 2026-03-24
CVE-2021-3875 vim is vulnerable to Heap-based Buffer Overflow Moderate vim 完成修复 2021-10-15 2026-03-24
CVE-2021-26318 A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result... Moderate kernel 完成修复 2021-10-13 2025-12-23
CVE-2021-22930 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit... Important nodejs:12 (Anolis OS 8.2), nodejs:12 (Anolis OS 8.4), nodejs:12, nodejs:14, nodejs 完成修复 2021-10-12 2026-01-06
CVE-2021-41116 Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to inst... Important composer 完成修复 2021-10-06 2026-01-07
CVE-2021-21684 Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when di... Moderate git 完成修复 2021-10-06 2026-07-11
CVE-2021-41103 containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in c... Moderate containerd 完成修复 2021-10-04 2026-03-24
CVE-2021-41092 Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `doc... Important docker 完成修复 2021-10-04 2026-01-08
CVE-2021-40324 Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. Important cobbler 完成修复 2021-10-04 2026-01-08
CVE-2021-40323 Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile f... Important cobbler 完成修复 2021-10-04 2026-01-08
CVE-2021-32762 Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service m... Important redis, redis:6, redis:5 完成修复 2021-10-04 2026-01-04
CVE-2021-32672 Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed ... Moderate redis 完成修复 2021-10-04 2026-01-25
CVE-2021-21706 In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::ex... Moderate php 完成修复 2021-10-04 2026-03-24
CVE-2021-21704 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malic... Moderate php:7.3, php:7.4, php 完成修复 2021-10-04 2026-03-24
CVE-2021-41106 JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-b... Low python-jwt 完成修复 2021-09-28 2026-01-25
CVE-2021-39246 Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 ... Moderate kernel 完成修复 2021-09-24 2025-12-23
CVE-2021-2464 Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vuln... Important kernel 完成修复 2021-09-24 2025-12-04
CVE-2021-33035 Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized ... Important libreoffice 完成修复 2021-09-23 2026-01-05
CVE-2021-3941 A vulnerability was found in openexr where a Divide-by-zero was found in Imf_3_1::RGBtoXYZ. References:\nhttps://bugs.chromi... Moderate OpenEXR 完成修复 2021-09-21 2026-03-24
CVE-2021-40325 Cobbler before 3.3.0 allows authorization bypass for modification of settings. Moderate cobbler 完成修复 2021-09-20 2026-07-13
CVE-2021-32280 An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() loc... Moderate transfig 完成修复 2021-09-20 2026-06-26
CVE-2020-21468 DISPUTED A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the ... Important redis, redis:6, redis:5 完成修复 2021-09-20 2026-01-04
CVE-2021-3807 ansi-regex is vulnerable to Inefficient Regular Expression Complexity Important nodejs:14, nodejs:16, nodejs 完成修复 2021-09-17 2026-01-06
CVE-2020-21534 fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c. Moderate transfig 完成修复 2021-09-16 2026-06-26
CVE-2020-21533 fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c. Moderate transfig 完成修复 2021-09-16 2026-06-26
CVE-2020-21530 fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. Moderate transfig 完成修复 2021-09-16 2026-06-26
CVE-2021-41079 Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When ... Important tomcat 完成修复 2021-09-15 2026-01-04
CVE-2021-41072 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-4015... Important squashfs-tools 完成修复 2021-09-14 2026-01-09
CVE-2021-40812 The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBu... Moderate gd 完成修复 2021-09-08 2026-07-13
CVE-2021-40346 An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggl... Important haproxy 完成修复 2021-09-08 2026-01-05
CVE-2021-30799 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur ... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30797 This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6,... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30795 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30762 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously... Moderate gnome-settings-daemon 完成修复 2021-09-08 2026-03-24
CVE-2021-30761 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing malicious... Moderate gnome-settings-daemon 完成修复 2021-09-08 2026-03-24
CVE-2021-30758 A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Su... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30749 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and ... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30744 Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is ... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30734 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and ... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30720 A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30689 A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari ... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30682 A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30666 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously ... Moderate gnome-settings-daemon 完成修复 2021-09-08 2026-03-24
CVE-2021-30665 A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iP... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30663 A flaw was found in the webkitgtk package. Affected versions of this package could allow a remote attacker to execute arbitrary... Moderate webkit2gtk3 完成修复 2021-09-08 2026-07-13
CVE-2021-30661 A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 ... Moderate gdm 完成修复 2021-09-08 2026-03-24
CVE-2021-1826 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, wa... Moderate gdm 完成修复 2021-09-08 2026-03-24
CVE-2021-1825 An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iClo... Moderate gdm 完成修复 2021-09-08 2026-03-24
CVE-2021-1820 A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 ... Moderate gdm 完成修复 2021-09-08 2026-03-24
CVE-2021-1817 A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and... Moderate gdm 完成修复 2021-09-08 2026-03-24
CVE-2021-24591 The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform C... Moderate highlight 完成修复 2021-09-06 2026-01-25
CVE-2021-39135 @npmcli/arborist, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm comm... Important nodejs:14, nodejs:16, nodejs, nodejs:12 完成修复 2021-08-31 2026-01-05
CVE-2021-39134 @npmcli/arborist, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm co... Important nodejs:14, nodejs:16, nodejs, nodejs:12 完成修复 2021-08-31 2026-01-05
CVE-2021-34558 The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matche... Moderate golang, container-tools:an8, go-toolset:an8 完成修复 2021-08-30 2025-12-11
CVE-2021-33196 In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewRead... Important golang, container-tools:2.0, buildah, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, go-toolset:an8 完成修复 2021-08-30 2025-12-11
CVE-2021-31162 In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element pa... Moderate rust-toolset:an8, rust-toolset, rust 完成修复 2021-08-30 2025-12-16
CVE-2021-28879 In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. ... Moderate rust-toolset:an8, rust 完成修复 2021-08-30 2025-12-16

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:32

results matching ""

    No results matching ""

    results matching ""

      No results matching ""