| CVE-2021-44420 |
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypa... |
Important |
python-django |
否 |
完成修复 |
2021-12-07 |
2026-01-04 |
| CVE-2021-43784 |
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used in... |
Low |
container-tools:4.0, container-tools:2.0, runc, container-tools:3.0, container-tools:an8, container-tools:1.0 |
是 |
完成修复 |
2021-12-06 |
2026-07-09 |
| CVE-2021-43565 |
There's an input validation flaw in golang.org/x/crypto's readCipherPacket() function. An unauthenticated attacker who sends an... |
Important |
docker, golang, go-toolset:an8 |
是 |
完成修复 |
2021-12-02 |
2025-12-17 |
| CVE-2021-34599 |
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git doe... |
Important |
git |
否 |
完成修复 |
2021-12-01 |
2026-01-06 |
| CVE-2021-38503 |
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as exec... |
Important |
thunderbird, firefox |
否 |
完成修复 |
2021-11-30 |
2026-01-04 |
| CVE-2021-44201 |
Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 ... |
Moderate |
kernel |
否 |
完成修复 |
2021-11-29 |
2025-12-17 |
| CVE-2021-3656 |
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virt... |
Important |
kernel:4.19, kernel:4.18, kernel, kernel:6.6, kernel:5.10, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(RHCK)4.18 (Anolis OS 8.2), kernel(ANCK)4.19 |
是 |
完成修复 |
2021-11-26 |
2025-12-04 |
| CVE-2021-3653 |
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virt... |
Important |
kernel:4.19, kernel:4.18, kernel:6.6, kernel:5.10, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(RHCK)4.18 (Anolis OS 8.2), kernel(ANCK)4.19 |
是 |
完成修复 |
2021-11-26 |
2025-12-04 |
| CVE-2021-26615 |
ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function beca... |
Important |
kernel |
否 |
完成修复 |
2021-11-26 |
2025-12-04 |
| CVE-2021-32037 |
An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation requ... |
Moderate |
mongodb |
是 |
完成修复 |
2021-11-24 |
2026-07-09 |
| CVE-2021-43267 |
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (T... |
Important |
kernel(RHCK)4.18 (Anolis OS 8.5), kernel, kernel(RHCK)4.18 (Anolis OS 8.4), kernel(ANCK) 5.10 |
是 |
完成修复 |
2021-11-23 |
2025-12-04 |
| CVE-2020-16156 |
CPAN 2.28 allows Signature Verification Bypass. |
Moderate |
perl-CPAN, perl, perl-any-uri-escape |
是 |
完成修复 |
2021-11-23 |
2026-03-24 |
| CVE-2021-23217 |
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated pri... |
Important |
kernel |
否 |
完成修复 |
2021-11-20 |
2025-12-04 |
| CVE-2021-33058 |
Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.... |
Important |
perl-version |
否 |
完成修复 |
2021-11-17 |
2026-01-04 |
| CVE-2021-42377 |
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when proces... |
Moderate |
busybox |
是 |
完成修复 |
2021-11-16 |
2026-03-24 |
| CVE-2021-37580 |
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authenti... |
Critical |
maven |
否 |
完成修复 |
2021-11-16 |
2026-01-10 |
| CVE-2021-43332 |
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admi... |
Moderate |
mailman |
是 |
完成修复 |
2021-11-13 |
2026-07-10 |
| CVE-2021-43331 |
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. |
Moderate |
mailman |
是 |
完成修复 |
2021-11-13 |
2026-07-10 |
| CVE-2020-23903 |
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of serv... |
Moderate |
speexdsp, speex |
是 |
完成修复 |
2021-11-11 |
2026-03-24 |
| CVE-2021-3572 |
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use... |
Low |
python27:2.7, python-pip, python38:3.8 |
是 |
完成修复 |
2021-11-10 |
2026-03-24 |
| CVE-2021-27645 |
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for... |
Low |
glibc |
否 |
完成修复 |
2021-11-09 |
2025-12-11 |
| CVE-2021-3928 |
vim is vulnerable to Use of Uninitialized Variable |
Important |
vim |
否 |
完成修复 |
2021-11-05 |
2026-01-04 |
| CVE-2021-29991 |
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header ... |
Important |
thunderbird |
否 |
完成修复 |
2021-11-03 |
2026-01-05 |
| CVE-2021-42697 |
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allow... |
Important |
httpd |
否 |
完成修复 |
2021-11-02 |
2026-01-09 |
| CVE-2017-5123 |
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. |
Important |
kernel |
是 |
完成修复 |
2021-11-02 |
2025-12-04 |
| CVE-2021-42694 |
An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adv... |
Moderate |
rust |
否 |
完成修复 |
2021-11-01 |
2025-12-16 |
| CVE-2021-41035 |
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible i... |
Moderate |
java-11-openjdk |
否 |
完成修复 |
2021-10-25 |
2025-12-05 |
| CVE-2021-22923 |
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metali... |
Moderate |
curl (Anolis OS 8.2), curl (Anolis OS 8.4), curl |
是 |
完成修复 |
2021-10-25 |
2026-03-24 |
| CVE-2021-22922 |
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the ... |
Moderate |
curl (Anolis OS 8.2), curl (Anolis OS 8.4), curl |
是 |
完成修复 |
2021-10-25 |
2026-03-24 |
| CVE-2020-27304 |
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in... |
Important |
ceph |
否 |
完成修复 |
2021-10-21 |
2026-01-08 |
| CVE-2021-35621 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35619 |
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, ... |
Important |
java-1.8.0-openjdk |
否 |
完成修复 |
2021-10-20 |
2025-12-05 |
| CVE-2021-35618 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Low |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35613 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Low |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35610 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected ... |
Important |
mariadb:10.5, mysql:8.0, mariadb, mysql |
否 |
完成修复 |
2021-10-20 |
2026-01-04 |
| CVE-2021-35598 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35594 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35593 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35592 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35590 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected ... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35584 |
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: ndbcluster/plugin DDL). Supported versions that... |
Moderate |
mysql |
是 |
完成修复 |
2021-10-20 |
2026-03-24 |
| CVE-2021-35560 |
Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java ... |
Important |
java-11-openjdk, icedtea-web, java-1.8.0-openjdk |
否 |
完成修复 |
2021-10-20 |
2025-12-05 |
| CVE-2021-35538 |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is aff... |
Important |
kernel |
否 |
完成修复 |
2021-10-20 |
2025-12-04 |
| CVE-2021-3746 |
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is trigge... |
Moderate |
libtpms |
是 |
完成修复 |
2021-10-19 |
2026-03-24 |
| CVE-2021-3875 |
vim is vulnerable to Heap-based Buffer Overflow |
Moderate |
vim |
是 |
完成修复 |
2021-10-15 |
2026-03-24 |
| CVE-2021-26318 |
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result... |
Moderate |
kernel |
否 |
完成修复 |
2021-10-13 |
2025-12-23 |
| CVE-2021-22930 |
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit... |
Important |
nodejs:12 (Anolis OS 8.2), nodejs:12 (Anolis OS 8.4), nodejs:12, nodejs:14, nodejs |
否 |
完成修复 |
2021-10-12 |
2026-01-06 |
| CVE-2021-41116 |
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to inst... |
Important |
composer |
否 |
完成修复 |
2021-10-06 |
2026-01-07 |
| CVE-2021-21684 |
Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when di... |
Moderate |
git |
是 |
完成修复 |
2021-10-06 |
2026-07-11 |
| CVE-2021-41103 |
containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in c... |
Moderate |
containerd |
是 |
完成修复 |
2021-10-04 |
2026-03-24 |
| CVE-2021-41092 |
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `doc... |
Important |
docker |
否 |
完成修复 |
2021-10-04 |
2026-01-08 |
| CVE-2021-40324 |
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. |
Important |
cobbler |
否 |
完成修复 |
2021-10-04 |
2026-01-08 |
| CVE-2021-40323 |
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile f... |
Important |
cobbler |
否 |
完成修复 |
2021-10-04 |
2026-01-08 |
| CVE-2021-32762 |
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service m... |
Important |
redis, redis:6, redis:5 |
否 |
完成修复 |
2021-10-04 |
2026-01-04 |
| CVE-2021-32672 |
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed ... |
Moderate |
redis |
否 |
完成修复 |
2021-10-04 |
2026-01-25 |
| CVE-2021-21706 |
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::ex... |
Moderate |
php |
是 |
完成修复 |
2021-10-04 |
2026-03-24 |
| CVE-2021-21704 |
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malic... |
Moderate |
php:7.3, php:7.4, php |
是 |
完成修复 |
2021-10-04 |
2026-03-24 |
| CVE-2021-41106 |
JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-b... |
Low |
python-jwt |
否 |
完成修复 |
2021-09-28 |
2026-01-25 |
| CVE-2021-39246 |
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 ... |
Moderate |
kernel |
否 |
完成修复 |
2021-09-24 |
2025-12-23 |
| CVE-2021-2464 |
Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vuln... |
Important |
kernel |
否 |
完成修复 |
2021-09-24 |
2025-12-04 |
| CVE-2021-33035 |
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized ... |
Important |
libreoffice |
否 |
完成修复 |
2021-09-23 |
2026-01-05 |
| CVE-2021-3941 |
A vulnerability was found in openexr where a Divide-by-zero was found in Imf_3_1::RGBtoXYZ. References:\nhttps://bugs.chromi... |
Moderate |
OpenEXR |
是 |
完成修复 |
2021-09-21 |
2026-03-24 |
| CVE-2021-40325 |
Cobbler before 3.3.0 allows authorization bypass for modification of settings. |
Moderate |
cobbler |
是 |
完成修复 |
2021-09-20 |
2026-07-13 |
| CVE-2021-32280 |
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() loc... |
Moderate |
transfig |
是 |
完成修复 |
2021-09-20 |
2026-06-26 |
| CVE-2020-21468 |
DISPUTED A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the ... |
Important |
redis, redis:6, redis:5 |
否 |
完成修复 |
2021-09-20 |
2026-01-04 |
| CVE-2021-3807 |
ansi-regex is vulnerable to Inefficient Regular Expression Complexity |
Important |
nodejs:14, nodejs:16, nodejs |
否 |
完成修复 |
2021-09-17 |
2026-01-06 |
| CVE-2020-21534 |
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c. |
Moderate |
transfig |
是 |
完成修复 |
2021-09-16 |
2026-06-26 |
| CVE-2020-21533 |
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c. |
Moderate |
transfig |
是 |
完成修复 |
2021-09-16 |
2026-06-26 |
| CVE-2020-21530 |
fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. |
Moderate |
transfig |
是 |
完成修复 |
2021-09-16 |
2026-06-26 |
| CVE-2021-41079 |
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When ... |
Important |
tomcat |
否 |
完成修复 |
2021-09-15 |
2026-01-04 |
| CVE-2021-41072 |
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-4015... |
Important |
squashfs-tools |
否 |
完成修复 |
2021-09-14 |
2026-01-09 |
| CVE-2021-40812 |
The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBu... |
Moderate |
gd |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-40346 |
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggl... |
Important |
haproxy |
否 |
完成修复 |
2021-09-08 |
2026-01-05 |
| CVE-2021-30799 |
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur ... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30797 |
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6,... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30795 |
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30762 |
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously... |
Moderate |
gnome-settings-daemon |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-30761 |
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing malicious... |
Moderate |
gnome-settings-daemon |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-30758 |
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Su... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30749 |
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and ... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30744 |
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is ... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30734 |
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and ... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30720 |
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30689 |
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari ... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30682 |
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30666 |
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously ... |
Moderate |
gnome-settings-daemon |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-30665 |
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iP... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30663 |
A flaw was found in the webkitgtk package. Affected versions of this package could allow a remote attacker to execute arbitrary... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2021-09-08 |
2026-07-13 |
| CVE-2021-30661 |
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 ... |
Moderate |
gdm |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-1826 |
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, wa... |
Moderate |
gdm |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-1825 |
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iClo... |
Moderate |
gdm |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-1820 |
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 ... |
Moderate |
gdm |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-1817 |
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and... |
Moderate |
gdm |
是 |
完成修复 |
2021-09-08 |
2026-03-24 |
| CVE-2021-24591 |
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform C... |
Moderate |
highlight |
否 |
完成修复 |
2021-09-06 |
2026-01-25 |
| CVE-2021-39135 |
@npmcli/arborist, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm comm... |
Important |
nodejs:14, nodejs:16, nodejs, nodejs:12 |
否 |
完成修复 |
2021-08-31 |
2026-01-05 |
| CVE-2021-39134 |
@npmcli/arborist, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm co... |
Important |
nodejs:14, nodejs:16, nodejs, nodejs:12 |
否 |
完成修复 |
2021-08-31 |
2026-01-05 |
| CVE-2021-34558 |
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matche... |
Moderate |
golang, container-tools:an8, go-toolset:an8 |
是 |
完成修复 |
2021-08-30 |
2025-12-11 |
| CVE-2021-33196 |
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewRead... |
Important |
golang, container-tools:2.0, buildah, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, go-toolset:an8 |
是 |
完成修复 |
2021-08-30 |
2025-12-11 |
| CVE-2021-31162 |
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element pa... |
Moderate |
rust-toolset:an8, rust-toolset, rust |
否 |
完成修复 |
2021-08-30 |
2025-12-16 |
| CVE-2021-28879 |
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. ... |
Moderate |
rust-toolset:an8, rust |
否 |
完成修复 |
2021-08-30 |
2025-12-16 |