CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-28878 In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the s... Important rust-toolset:an8, rust 完成修复 2021-08-30 2025-12-16
CVE-2021-28877 In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more ... Important rust-toolset:an8, rust 完成修复 2021-08-30 2025-12-16
CVE-2021-28875 In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.... Important rust-toolset:an8, rust 完成修复 2021-08-30 2025-12-16
CVE-2021-40145 DISPUTED gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vend... Important gd 完成修复 2021-08-25 2026-01-07
CVE-2021-32066 An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exceptio... Important ruby, ruby:3.0, ruby:2.6, ruby:2.5, ruby:2.7, ruby:3.3 完成修复 2021-08-25 2026-01-04
CVE-2020-18974 Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the componen... Low nasm 完成修复 2021-08-25 2026-03-24
CVE-2021-30860 An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS... Important poppler 完成修复 2021-08-24 2026-01-04
CVE-2021-29985 A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This ... Important firefox, thunderbird 完成修复 2021-08-24 2026-01-04
CVE-2021-37714 jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be... Moderate jsoup 完成修复 2021-08-18 2026-07-09
CVE-2020-10543 Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have a... Important perl 完成修复 2021-08-18 2026-01-05
CVE-2021-39242 An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with ... Important haproxy 完成修复 2021-08-17 2026-01-05
CVE-2021-39241 An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP metho... Important haproxy 完成修复 2021-08-17 2026-01-05
CVE-2021-39240 An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the sche... Important haproxy 完成修复 2021-08-17 2026-01-05
CVE-2021-29987 After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed i... Moderate thunderbird, firefox 完成修复 2021-08-17 2026-01-24
CVE-2021-29982 Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential le... Moderate thunderbird, firefox 完成修复 2021-08-17 2026-01-24
CVE-2021-29981 An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JIT... Important thunderbird 完成修复 2021-08-17 2026-01-05
CVE-2020-28165 The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrar... Important jetty 完成修复 2021-08-12 2026-01-06
CVE-2021-38511 An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can cre... Moderate tar 完成修复 2021-08-10 2026-01-25
CVE-2021-37623 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An i... Moderate exiv2 完成修复 2021-08-09 2026-07-11
CVE-2021-37621 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An i... Moderate exiv2 完成修复 2021-08-09 2026-07-11
CVE-2021-37616 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A nu... Moderate exiv2 完成修复 2021-08-09 2026-07-11
CVE-2021-37615 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A nu... Moderate exiv2 完成修复 2021-08-09 2026-07-11
CVE-2021-34335 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A fl... Moderate exiv2 完成修复 2021-08-09 2026-07-11
CVE-2021-37622 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An i... Moderate exiv2 完成修复 2021-08-08 2026-07-11
CVE-2021-37620 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An o... Moderate exiv2 完成修复 2021-08-08 2026-07-11
CVE-2021-36221 Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an... Moderate golang, container-tools:2.0, buildah, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, go-toolset:an8 完成修复 2021-08-08 2025-12-11
CVE-2021-34334 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An i... Moderate exiv2 完成修复 2021-08-08 2026-07-11
CVE-2021-32815 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The ... Moderate exiv2 完成修复 2021-08-08 2026-07-11
CVE-2021-29922 library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of a... Moderate rust-toolset 完成修复 2021-08-07 2025-12-16
CVE-2021-38165 Moderate lynx 完成修复 2021-08-06 2026-07-10
CVE-2021-29971 If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of sc... Important firefox 完成修复 2021-08-06 2026-01-04
CVE-2021-3580 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this ... Moderate nettle 完成修复 2021-08-05 2026-03-24
CVE-2021-28216 BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support ... Important edk2 完成修复 2021-08-05 2026-01-08
CVE-2021-22925 curl supports the -t command line option, known as CURLOPT_TELNETOPTIONSin libcurl. This rarely used option is used to send... Low curl 完成修复 2021-08-05 2026-03-24
CVE-2021-38115 read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of s... Moderate gd 完成修复 2021-08-04 2026-07-13
CVE-2021-32804 The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vu... Important nodejs, nodejs:12 (Anolis OS 8.4), nodejs:12, nodejs:14, nodejs:12 (Anolis OS 8.2) 完成修复 2021-08-03 2026-01-06
CVE-2021-32803 The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite v... Important nodejs, nodejs:12 (Anolis OS 8.4), nodejs:12, nodejs:14, nodejs:12 (Anolis OS 8.2) 完成修复 2021-08-03 2026-01-06
CVE-2021-30569 Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corrupti... Important sqlite 完成修复 2021-08-03 2026-01-09
CVE-2021-33195 Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thu... Important golang, container-tools:2.0, buildah, container-tools:an8, container-tools:3.0, container-tools:4.0, go-toolset:an8 完成修复 2021-08-02 2025-12-11
CVE-2021-37595 In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input ch... Critical freerdp 完成修复 2021-07-30 2026-01-09
CVE-2021-37594 In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input ch... Critical freerdp 完成修复 2021-07-30 2026-01-10
CVE-2021-32610 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CV... Moderate php-pear 完成修复 2021-07-30 2026-03-24
CVE-2021-31292 An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause ... Moderate exiv2, compat-exiv2-026 完成修复 2021-07-26 2026-07-11
CVE-2015-2100 Multiple stack-based buffer overflows in WebGate eDVR Manager and Control Center allow remote attackers to execute arbitrary co... Important control-center 完成修复 2021-07-22 2026-01-07
CVE-2015-2099 Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to... Important control-center 完成修复 2021-07-22 2026-01-07
CVE-2021-32761 Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buff... Important redis, redis:6, redis:5 完成修复 2021-07-21 2026-01-04
CVE-2021-2432 Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u... Moderate java-11-openjdk 完成修复 2021-07-21 2025-12-05
CVE-2021-2411 Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module). Supported versions that are affecte... Low mysql 完成修复 2021-07-21 2026-03-24
CVE-2020-15660 Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired... Moderate firefox 完成修复 2021-07-20 2026-01-24
CVE-2021-32774 DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataD... Moderate perl-Data-Dump 完成修复 2021-07-19 2026-03-24
CVE-2021-3520 There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integ... Important lz4 完成修复 2021-07-16 2026-01-04
CVE-2021-30465 runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacke... Important container-tools:2.0, container-tools:3.0, container-tools:an8, container-tools:4.0, container-tools:1.0, runc, container-tools:2.0 (Anolis OS 8.4), container-tools:2.0 (Anolis OS 8.2) 完成修复 2021-07-15 2026-01-07
CVE-2021-29742 IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483. Important docker 完成修复 2021-07-15 2026-01-08
CVE-2021-29699 IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file typ... Moderate docker 完成修复 2021-07-15 2026-03-24
CVE-2021-27845 A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c Moderate jasper 完成修复 2021-07-15 2026-07-09
CVE-2021-25217 In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x s... Important dhcp (Anolis OS 8.4), dhcp, dhcp (Anolis OS 8.2) 完成修复 2021-07-15 2026-01-06
CVE-2021-20534 IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect atta... Moderate docker 完成修复 2021-07-15 2026-03-24
CVE-2021-20533 IBM Security Verify Access Docker 10.0.0 could allow a remote authenticated attacker to execute arbitrary commands on the syste... Important docker 完成修复 2021-07-15 2026-01-08
CVE-2021-20524 IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... Moderate docker 完成修复 2021-07-15 2026-03-24
CVE-2021-20523 IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technica... Low docker 完成修复 2021-07-15 2026-03-24
CVE-2021-20499 IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technica... Low docker 完成修复 2021-07-15 2026-03-24
CVE-2021-20498 IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks aga... Moderate docker 完成修复 2021-07-15 2026-03-24
CVE-2021-20497 IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to dec... Moderate docker 完成修复 2021-07-15 2026-03-24
CVE-2019-11098 Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of pr... Moderate edk2 完成修复 2021-07-14 2026-03-24
CVE-2021-36373 When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally l... Moderate ant 完成修复 2021-07-13 2026-03-24
CVE-2021-22921 Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Win... Important nodejs 完成修复 2021-07-12 2026-01-06
CVE-2021-3571 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP... Moderate linuxptp 完成修复 2021-07-09 2026-07-11
CVE-2021-20024 Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system i... Important perl-Switch 完成修复 2021-07-09 2026-01-04
CVE-2012-2666 golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file ... Important golang 完成修复 2021-07-09 2025-12-11
CVE-2021-21806 An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page c... Moderate webkit2gtk3 完成修复 2021-07-08 2026-07-13
CVE-2021-21779 A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A speci... Moderate webkit2gtk3 完成修复 2021-07-08 2026-07-13
CVE-2021-32715 hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `C... Moderate rust 完成修复 2021-07-07 2025-12-16
CVE-2021-32714 hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trig... Moderate rust 完成修复 2021-07-07 2025-12-16
CVE-2021-21775 A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.... Moderate webkit2gtk3 完成修复 2021-07-07 2026-07-13
CVE-2021-3598 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submi... Moderate OpenEXR 完成修复 2021-07-06 2026-03-24
CVE-2021-35331 DISPUTED In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: ... Important tcl 完成修复 2021-07-05 2026-01-04
CVE-2021-33516 An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server ca... Important gupnp, gupnp (Anolis OS 8.4), gupnp (Anolis OS 8.2) 完成修复 2021-07-05 2026-01-05
CVE-2021-27219 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow ... Important glib2 (Anolis OS 8.4), glib2, glib2 (Anolis OS 8.2) 完成修复 2021-07-05 2026-01-09
CVE-2020-36329 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The hi... Important libwebp, libwebp (Anolis OS 8.4), libwebp (Anolis OS 8.2) 完成修复 2021-07-05 2026-01-05
CVE-2020-36328 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible du... Important libwebp, libwebp (Anolis OS 8.4), libwebp (Anolis OS 8.2) 完成修复 2021-07-05 2026-01-05
CVE-2018-25011 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow was found in PutLE16(). The highest threat f... Important libwebp, libwebp (Anolis OS 8.4), libwebp (Anolis OS 8.2) 完成修复 2021-07-05 2026-01-05
CVE-2021-35042 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a ... Important python-django 完成修复 2021-07-02 2026-01-04
CVE-2021-36086 The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil... Moderate libsepol 完成修复 2021-07-01 2026-03-24
CVE-2021-36085 The CIL compiler in SELinux 3.2 has a use-after-free in cil_verify_classperms (called from verify_map_perm_classperms and h... Moderate libsepol 完成修复 2021-07-01 2026-03-24
CVE-2021-36084 The CIL compiler in SELinux 3.2 has a use-after-free in cil_verify_classperms (called from cilverify_classpermission and ... Moderate libsepol 完成修复 2021-07-01 2026-07-11
CVE-2021-36087 The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_nevera... Moderate libsepol 完成修复 2021-06-30 2026-07-11
CVE-2021-36081 Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. Important tesseract 完成修复 2021-06-30 2026-01-05
CVE-2021-35942 The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/... Moderate glibc 完成修复 2021-06-30 2025-12-11
CVE-2020-36404 Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl::~SmallVectorImpl. Important kernel 完成修复 2021-06-30 2025-12-04
CVE-2020-36402 Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a28... Important kernel 完成修复 2021-06-30 2025-12-04
CVE-2021-3620 A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credential... Important ansible-core 完成修复 2021-06-25 2026-01-06
CVE-2021-0561 In appendto_verify_fifo_interleaved of stream_encoder.c, there is a possible out of bounds write due to a missing bounds chec... Moderate flac 完成修复 2021-06-22 2026-03-24
CVE-2021-0535 In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could ... Moderate wpa_supplicant 完成修复 2021-06-22 2026-03-24
CVE-2020-36394 pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbit... Important pam 完成修复 2021-06-22 2026-01-09
CVE-2010-2525 A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker coul... Important kernel 完成修复 2021-06-22 2025-12-04
CVE-2021-39365 Moderate grilo 完成修复 2021-06-20 2026-07-11
CVE-2020-18442 Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in... Low zziplib 完成修复 2021-06-18 2026-07-09
CVE-2021-3603 PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected in... Important php 完成修复 2021-06-17 2026-01-04
CVE-2021-34812 Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to ... Important ocaml-calendar 完成修复 2021-06-17 2026-01-05
CVE-2021-34551 PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. Important php 完成修复 2021-06-16 2026-01-04

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:32

results matching ""

    No results matching ""

    results matching ""

      No results matching ""