CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-20566 IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens... Moderate kernel 完成修复 2021-06-16 2025-12-17
CVE-2021-3605 There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted... Moderate OpenEXR 完成修复 2021-06-11 2026-03-24
CVE-2021-22898 curl 7.7 through 7.76.1 suffers from an information disclosure when the -t command line option, known as `CURLOPT_TELNETOPTIO... Low curl 完成修复 2021-06-11 2026-03-24
CVE-2021-20293 A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did n... Moderate resteasy 完成修复 2021-06-10 2026-07-10
CVE-2021-30641 Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' Moderate httpd:2.4, httpd 完成修复 2021-06-09 2026-07-10
CVE-2021-26690 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer d... Moderate httpd 完成修复 2021-06-09 2026-07-11
CVE-2019-17567 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the ori... Moderate httpd 完成修复 2021-06-09 2026-07-11
CVE-2021-33560 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a sid... Moderate libgcrypt 完成修复 2021-06-08 2026-01-25
CVE-2021-30535 Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via ... Important icu 完成修复 2021-06-07 2026-01-05
CVE-2018-25015 An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock afte... Important kernel 完成修复 2021-06-07 2025-12-04
CVE-2017-20005 NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date... Important nginx 完成修复 2021-06-06 2026-01-06
CVE-2021-30475 aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. Important aom 完成修复 2021-06-04 2026-01-06
CVE-2021-3569 A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This fla... Moderate libtpms 完成修复 2021-06-03 2026-03-24
CVE-2021-30474 aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. Moderate aom 完成修复 2021-06-03 2026-03-24
CVE-2019-14584 Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via lo... Moderate edk2 完成修复 2021-06-03 2026-07-12
CVE-2020-24870 Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp. Important LibRaw 完成修复 2021-06-02 2026-01-05
CVE-2009-0948 Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file befor... Critical file, filesystem 完成修复 2021-06-02 2026-01-10
CVE-2009-0947 Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02. Critical file, file-roller 完成修复 2021-06-02 2026-01-10
CVE-2021-33503 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority compon... Important python39:3.9, python-urllib3 完成修复 2021-06-01 2026-01-09
CVE-2021-33183 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management compon... Important docker 完成修复 2021-06-01 2026-01-08
CVE-2020-27748 A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows atta... Moderate xdg-utils 完成修复 2021-06-01 2026-07-11
CVE-2021-20236 A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer ove... Moderate zeromq, zeromq3 完成修复 2021-05-28 2026-03-24
CVE-2021-20201 A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of... Low spice 完成修复 2021-05-28 2026-03-24
CVE-2020-1716 A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords ... Important ceph 完成修复 2021-05-28 2026-01-08
CVE-2013-4536 An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt ... Important qemu, qemu-kvm 完成修复 2021-05-28 2025-12-09
CVE-2021-31535 LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX... Moderate libX11 完成修复 2021-05-27 2026-01-25
CVE-2020-14301 An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-base... Low libvirt, virt:an 完成修复 2021-05-27 2025-12-18
CVE-2008-2544 Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environmen... Low kernel 5.10, kernel 4.19 完成修复 2021-05-27 2026-01-23
CVE-2021-33194 golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via cr... Important golang, container-tools:2.0, buildah, container-tools:an8, container-tools:3.0, container-tools:4.0, container-tools:1.0, go-toolset:an8 完成修复 2021-05-26 2025-12-10
CVE-2009-3721 Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that ... Important evolution 完成修复 2021-05-26 2026-01-07
CVE-2021-33574 The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notificatio... Low glibc 完成修复 2021-05-25 2025-12-11
CVE-2021-3565 A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrappe... Moderate tpm2-tools 完成修复 2021-05-24 2026-06-26
CVE-2020-20178 Ethereum 0xe933c0cd9784414d5f278c114904f5a84b396919#code.sol latest version is affected by a denial of service vulnerability in... Important openldap 完成修复 2021-05-24 2026-01-09
CVE-2018-25014 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). Moderate libwebp 完成修复 2021-05-21 2026-03-24
CVE-2018-25012 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). Moderate libwebp 完成修复 2021-05-21 2026-03-24
CVE-2018-25010 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). Moderate libwebp 完成修复 2021-05-21 2026-03-24
CVE-2018-25009 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). Moderate libwebp 完成修复 2021-05-21 2026-03-24
CVE-2021-41496 Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial... Important numpy 完成修复 2021-05-13 2026-01-05
CVE-2021-32921 An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret string... Moderate lua 完成修复 2021-05-13 2026-01-25
CVE-2021-32918 An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service ... Important lua 完成修复 2021-05-13 2026-01-04
CVE-2020-27824 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who ca... Low openjpeg2 完成修复 2021-05-13 2026-03-27
CVE-2020-27823 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG t... Moderate openjpeg2 完成修复 2021-05-13 2026-03-27
CVE-2020-25713 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. Low raptor2 完成修复 2021-05-13 2026-07-10
CVE-2021-34141 An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorre... Moderate numpy 完成修复 2021-05-11 2026-01-25
CVE-2021-32056 Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrict... Moderate cyrus-imapd 完成修复 2021-05-10 2026-07-13
CVE-2019-16163 Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. Moderate oniguruma, php:7.3 完成修复 2021-05-08 2026-03-27
CVE-2019-13224 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosu... Moderate oniguruma, php:7.3 完成修复 2021-05-08 2026-03-24
CVE-2021-3502 A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local... Moderate avahi 完成修复 2021-05-07 2026-07-11
CVE-2021-3507 A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer... Low sgabios 完成修复 2021-05-06 2026-07-10
CVE-2021-30473 aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. Moderate aom 完成修复 2021-05-06 2026-03-24
CVE-2021-29369 The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. Critical gnuplot 完成修复 2021-05-03 2026-01-10
CVE-2021-25631 In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be... Important libreoffice 完成修复 2021-05-03 2026-01-05
CVE-2021-3575 A heap-based buffer overflow was found in OpenJPEG. This flaw allows an attacker to execute arbitrary code with the permissions... Moderate openjpeg2 完成修复 2021-05-01 2026-03-27
CVE-2021-20326 A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects: MongoDB Inc.... Moderate mongodb 完成修复 2021-04-30 2026-07-09
CVE-2021-31879 GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-20... Moderate wget 完成修复 2021-04-29 2026-03-24
CVE-2020-18032 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute ar... Moderate graphviz 完成修复 2021-04-29 2026-07-11
CVE-2020-16845 Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via in... Important gcc, golang, xz, go-toolset:an8 完成修复 2021-04-29 2025-12-10
CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering a... Important golang, go-toolset:an8 完成修复 2021-04-29 2025-12-10
CVE-2021-29482 xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used... Important xz 完成修复 2021-04-28 2025-12-13
CVE-2021-29476 Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched ... Critical python-requests 完成修复 2021-04-27 2026-01-09
CVE-2020-36326 PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE:... Critical php 完成修复 2021-04-27 2026-01-09
CVE-2019-25042 DISPUTED Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor dispute... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25041 DISPUTED Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor dispu... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25040 DISPUTED Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes ... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25039 DISPUTED Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor dispu... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25038 DISPUTED Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor d... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25037 DISPUTED Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. ... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25036 DISPUTED Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25035 DISPUTED Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this ... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25034 DISPUTED Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds ... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2019-25032 DISPUTED Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor d... Moderate unbound 完成修复 2021-04-27 2026-01-25
CVE-2021-3472 A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a l... Important xorg-x11-server 完成修复 2021-04-26 2026-01-04
CVE-2021-22884 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “local... Important nodejs, nodejs:14, nodejs:12, nodejs:10 完成修复 2021-04-26 2026-01-06
CVE-2019-25033 DISPUTED Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vend... Moderate unbound 完成修复 2021-04-26 2026-01-25
CVE-2021-2019 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that ar... Low mysql:8.0, mysql 完成修复 2021-04-25 2026-03-24
CVE-2021-29469 Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detect... Important redis 完成修复 2021-04-23 2026-01-04
CVE-2021-22207 Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via p... Moderate wireshark 完成修复 2021-04-23 2026-01-25
CVE-2020-12663 Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. Important unbound 完成修复 2021-04-22 2026-01-06
CVE-2020-12662 Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by rando... Important unbound 完成修复 2021-04-22 2026-01-06
CVE-2021-3156 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escala... Important sudo 完成修复 2021-04-21 2026-01-08
CVE-2021-29462 The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of p... Important libupnp 完成修复 2021-04-21 2026-01-04
CVE-2021-3505 A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength du... Moderate libtpms 完成修复 2021-04-19 2026-03-27
CVE-2021-29457 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A he... Important exiv2 完成修复 2021-04-19 2026-01-07
CVE-2021-29399 XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of X... Moderate php 完成修复 2021-04-19 2026-03-24
CVE-2021-29444 jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_... Moderate jose 完成修复 2021-04-16 2026-03-24
CVE-2021-29443 jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128... Moderate jose 完成修复 2021-04-16 2026-07-09
CVE-2021-29338 OpenJPEGv2.4.0中的整数溢出允许远程攻击者使应用程序崩溃,从而导致拒绝服务(DoS)。当攻击者在包... Moderate openjpeg2 完成修复 2021-04-14 2026-07-10
CVE-2021-27608 An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is... Important setup 完成修复 2021-04-14 2026-01-09
CVE-2021-27905 The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leader... Important lucene 完成修复 2021-04-13 2026-01-05
CVE-2018-25008 In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization i... Moderate rust 完成修复 2021-04-13 2025-12-17
CVE-2017-20004 In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be ... Moderate rust 完成修复 2021-04-13 2025-12-17
CVE-2021-29943 When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy di... Important lucene 完成修复 2021-04-12 2026-01-05
CVE-2021-29425 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo... Moderate apache-commons-io, maven:3.5, maven:3.6 完成修复 2021-04-12 2026-03-24
CVE-2021-29262 When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLPr... Moderate lucene 完成修复 2021-04-12 2026-07-10
CVE-2020-36318 In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once un... Low rust-toolset 完成修复 2021-04-11 2025-12-17
CVE-2020-36317 In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a no... Moderate rust-toolset:an8, rust 完成修复 2021-04-11 2025-12-16
CVE-2015-20001 In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state wh... Important rust 完成修复 2021-04-11 2025-12-16
CVE-2021-3448 A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dn... Moderate dnsmasq 完成修复 2021-04-09 2026-03-24
CVE-2020-36309 ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the A... Moderate nginx 完成修复 2021-04-06 2026-01-25
CVE-2021-28832 VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration. Important vim 完成修复 2021-04-04 2026-01-06

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:32

results matching ""

    No results matching ""

    results matching ""

      No results matching ""