CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-1871 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Cat... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1870 A logic issue was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. A remote attacker may be able to cause arbitra... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1801 A flaw was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. Maliciously crafted web content may violate the ifram... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1799 A port redirection issue was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. A malicious website may be able to ... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1789 A type confusion vulnerability was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. Processing maliciously crafte... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1788 A use-after-free issue was found in WebKitGTK and WPE WebKit in versions prior to 2.32.0. Processing maliciously crafted web co... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2021-1765 A flaw was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. Maliciously crafted web content may violate the ifram... Moderate webkit2gtk3 完成修复 2021-04-02 2026-07-13
CVE-2020-9926 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.... Important libxml2 完成修复 2021-04-02 2026-01-09
CVE-2020-29623 "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is ... Low webkit2gtk3 完成修复 2021-04-02 2026-07-09
CVE-2020-27920 A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Updat... Important libxml2 完成修复 2021-04-02 2026-01-09
CVE-2020-10001 An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Upda... Moderate cups 完成修复 2021-04-02 2026-03-24
CVE-2021-28165 In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving... Important jetty 完成修复 2021-04-01 2026-01-06
CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by l... Moderate curl 完成修复 2021-04-01 2026-03-24
CVE-2021-3470 A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator o... Moderate redis, redis:6, redis:5 完成修复 2021-03-31 2026-03-24
CVE-2021-20289 A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as... Low resteasy 完成修复 2021-03-26 2026-07-10
CVE-2021-20197 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcop... Moderate binutils 完成修复 2021-03-26 2025-12-11
CVE-2021-20193 A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to... Moderate tar 完成修复 2021-03-26 2026-03-24
CVE-2021-3467 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in ... Moderate jasper 完成修复 2021-03-25 2026-03-27
CVE-2021-3443 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 imag... Moderate jasper 完成修复 2021-03-25 2026-03-27
CVE-2020-27918 A use-after-free issue was found in WebKitGTK and WPE WebKit in versions prior to 2.30.6. Processing maliciously crafted web co... Moderate webkit2gtk3 完成修复 2021-03-21 2026-07-13
CVE-2019-10128 A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL... Important postgresql:15, postgresql 完成修复 2021-03-19 2026-01-04
CVE-2019-10127 A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does ... Important postgresql:15, postgresql 完成修复 2021-03-19 2026-01-04
CVE-2021-28667 StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can o... Important python 完成修复 2021-03-17 2026-01-04
CVE-2021-28650 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory T... Low webkit2gtk3 完成修复 2021-03-17 2026-07-09
CVE-2021-26945 An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this... Moderate OpenEXR 完成修复 2021-03-17 2026-03-24
CVE-2021-26260 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An at... Moderate OpenEXR 完成修复 2021-03-17 2026-03-24
CVE-2021-23215 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An at... Moderate OpenEXR 完成修复 2021-03-17 2026-03-24
CVE-2021-23169 A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use... Important OpenEXR 完成修复 2021-03-17 2026-01-05
CVE-2021-3475 There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR ... Moderate OpenEXR 完成修复 2021-03-15 2026-03-24
CVE-2021-3474 There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift ... Moderate OpenEXR 完成修复 2021-03-15 2026-03-24
CVE-2021-27290 ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicio... Important nodejs, nodejs:12 (Anolis OS 8.4), nodejs:12, nodejs:14, nodejs:12 (Anolis OS 8.2) 完成修复 2021-03-12 2026-01-06
CVE-2020-36278 Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. Important leptonica 完成修复 2021-03-12 2026-01-06
CVE-2020-36281 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. Important leptonica 完成修复 2021-03-11 2026-01-06
CVE-2020-36280 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. Important leptonica 完成修复 2021-03-11 2026-01-06
CVE-2020-36279 Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. Important leptonica 完成修复 2021-03-11 2026-01-06
CVE-2020-36277 Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv... Important leptonica 完成修复 2021-03-11 2026-01-06
CVE-2020-13959 The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as par... Moderate velocity, pki-deps:10.6 完成修复 2021-03-10 2026-06-26
CVE-2020-13936 An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the... Important velocity 完成修复 2021-03-10 2025-12-30
CVE-2021-21179 Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially ex... Important kernel 完成修复 2021-03-09 2025-12-04
CVE-2020-35524 A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially c... Moderate libtiff 完成修复 2021-03-09 2026-03-24
CVE-2020-35523 An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject an... Moderate libtiff 完成修复 2021-03-09 2026-03-24
CVE-2020-35522 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a re... Low libtiff 完成修复 2021-03-09 2026-03-24
CVE-2020-35521 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, result... Low libtiff 完成修复 2021-03-09 2026-03-23
CVE-2021-28041 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained ag... Moderate openssh 完成修复 2021-03-05 2026-01-25
CVE-2020-13558 A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially... Moderate webkit2gtk3 完成修复 2021-03-03 2026-07-13
CVE-2020-7929 A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type o... Moderate mongodb 完成修复 2021-03-01 2026-06-24
CVE-2018-25004 A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command o... Moderate mongodb 完成修复 2021-03-01 2026-06-24
CVE-2021-25289 An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files b... Important python-pillow 完成修复 2021-02-28 2026-01-04
CVE-2021-23979 Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption a... Moderate kernel 完成修复 2021-02-26 2026-01-22
CVE-2021-21309 Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-... Important redis, redis:6, redis:5 完成修复 2021-02-26 2026-01-04
CVE-2020-27618 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequenc... Low glibc 完成修复 2021-02-26 2025-12-11
CVE-2020-27223 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing mu... Moderate jetty 完成修复 2021-02-26 2026-07-09
CVE-2020-8032 A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate t... Important cyrus-sasl 完成修复 2021-02-25 2026-01-06
CVE-2021-21974 OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a... Important openslp 完成修复 2021-02-24 2026-01-05
CVE-2021-26927 A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and d... Moderate jasper, perl-version 完成修复 2021-02-23 2026-03-23
CVE-2021-26926 A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclos... Moderate jasper 完成修复 2021-02-23 2026-03-27
CVE-2021-27378 An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain... Critical rust 完成修复 2021-02-18 2025-12-17
CVE-2021-20446 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... Moderate kernel 完成修复 2021-02-18 2025-12-23
CVE-2021-20444 IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... Moderate kernel 完成修复 2021-02-18 2025-12-23
CVE-2021-20354 IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could sen... Moderate kernel 完成修复 2021-02-18 2025-12-23
CVE-2020-4933 IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows user... Moderate kernel 完成修复 2021-02-18 2025-12-23
CVE-2021-27367 Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Director... Important bolt 完成修复 2021-02-17 2026-01-05
CVE-2020-12372 Unchecked return value in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potential... Moderate linux-firmware 完成修复 2021-02-17 2026-03-23
CVE-2020-12368 Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially ena... Important linux-firmware 完成修复 2021-02-17 2026-01-05
CVE-2021-23840 Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where ... Important openssl098e, nodejs, edk2, openssl, compat-openssl10, ovmf 完成修复 2021-02-16 2026-01-09
CVE-2021-43616 The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-loc... Important nodejs:14, nodejs:16, nodejs, nodejs:12 完成修复 2021-02-15 2026-01-05
CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a craft... Moderate OpenEXR 完成修复 2021-02-15 2026-03-23
CVE-2021-3477 There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit... Moderate OpenEXR 完成修复 2021-02-15 2026-03-23
CVE-2021-3476 A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit ... Moderate OpenEXR 完成修复 2021-02-15 2026-03-23
CVE-2021-21702 In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP se... Low php-pecl-zip 完成修复 2021-02-15 2026-07-10
CVE-2021-20296 A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by t... Moderate OpenEXR 完成修复 2021-02-15 2026-03-23
CVE-2020-7071 In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILT... Moderate php-pecl-zip, php:7.4 完成修复 2021-02-15 2026-07-10
CVE-2020-35512 A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x a... Important dbusmenu-qt, dbus-python 完成修复 2021-02-15 2026-01-04
CVE-2021-20411 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incor... Important kernel 完成修复 2021-02-12 2025-12-04
CVE-2021-20408 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inprop... Important kernel 完成修复 2021-02-12 2025-12-04
CVE-2020-8027 A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for ... Moderate openldap 完成修复 2021-02-11 2026-03-23
CVE-2021-0326 In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to rem... Moderate wpa_supplicant 完成修复 2021-02-10 2026-03-23
CVE-2019-19005 Moderate autotrace 完成修复 2021-02-10 2026-03-23
CVE-2019-19004 Low autotrace 完成修复 2021-02-10 2026-03-23
CVE-2021-26719 A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-... Moderate maven 完成修复 2021-02-09 2026-01-25
CVE-2021-21240 httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which respond... Low python-httplib2 完成修复 2021-02-08 2026-03-27
CVE-2020-14312 A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red H... Moderate dnsmasq 完成修复 2021-02-06 2026-03-23
CVE-2020-36241 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory ... Low webkit2gtk3 完成修复 2021-02-05 2026-01-04
CVE-2020-28403 A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attack... Important star 完成修复 2021-01-29 2026-01-08
CVE-2020-35517 A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privil... Important qemu-kvm 完成修复 2021-01-28 2025-12-09
CVE-2021-3326 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the I... Moderate glibc 完成修复 2021-01-27 2025-12-11
CVE-2021-3272 jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationsh... Moderate jasper 完成修复 2021-01-27 2026-03-27
CVE-2021-3185 A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacke... Moderate gstreamer1-plugins-good, gstreamer1-plugins-bad-free, gstreamer1, gstreamer1-plugins-base 完成修复 2021-01-26 2026-07-11
CVE-2021-3115 Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using t... Moderate golang-dbus, golang 完成修复 2021-01-26 2025-12-10
CVE-2021-25900 An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflo... Important librsvg2 完成修复 2021-01-26 2026-01-05
CVE-2020-36204 An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send trait o... Moderate rust 完成修复 2021-01-26 2025-12-17
CVE-2020-29443 ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validate... Moderate libvirt 完成修复 2021-01-26 2025-12-18
CVE-2020-27814 A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to caus... Moderate openjpeg2 完成修复 2021-01-26 2026-03-27
CVE-2020-4921 IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen... Important kernel 完成修复 2021-01-20 2025-12-04
CVE-2020-27221 In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machi... Critical java-11-openjdk, eclipse 完成修复 2021-01-20 2025-12-05
CVE-2020-14360 A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a pr... Moderate libwacom 完成修复 2021-01-20 2026-03-23
CVE-2021-21237 Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repositor... Important git 完成修复 2021-01-15 2026-01-06
CVE-2021-21009 Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3... Important kernel 完成修复 2021-01-13 2025-12-04
CVE-2020-4597 IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers ma... Moderate kernel 完成修复 2021-01-13 2025-12-23
CVE-2021-3121 An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "s... Important protobuf 完成修复 2021-01-11 2026-01-04

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:32

results matching ""

    No results matching ""

    results matching ""

      No results matching ""