| CVE-2021-23240 |
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate ... |
Important |
sudo |
否 |
完成修复 |
2021-01-11 |
2026-01-08 |
| CVE-2021-23239 |
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence test... |
Low |
sudo |
否 |
完成修复 |
2021-01-11 |
2026-01-25 |
| CVE-2021-0308 |
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to l... |
Moderate |
gdisk |
是 |
完成修复 |
2021-01-11 |
2026-03-23 |
| CVE-2021-1060 |
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not v... |
Important |
kernel |
否 |
完成修复 |
2021-01-08 |
2025-12-04 |
| CVE-2021-1056 |
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it do... |
Important |
libnvidia-container |
否 |
完成修复 |
2021-01-08 |
2026-01-05 |
| CVE-2021-1052 |
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys)... |
Important |
libnvidia-container |
否 |
完成修复 |
2021-01-08 |
2026-01-05 |
| CVE-2020-5022 |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can resul... |
Moderate |
kernel |
否 |
完成修复 |
2021-01-08 |
2025-12-09 |
| CVE-2020-5019 |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input ... |
Moderate |
kernel |
否 |
完成修复 |
2021-01-08 |
2025-12-23 |
| CVE-2020-5018 |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such infor... |
Low |
kernel |
是 |
完成修复 |
2021-01-08 |
2026-01-23 |
| CVE-2020-5017 |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended ro... |
Low |
kernel |
是 |
完成修复 |
2021-01-08 |
2026-01-23 |
| CVE-2020-26972 |
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not... |
Important |
firefox |
否 |
完成修复 |
2021-01-07 |
2026-01-04 |
| CVE-2018-18689 |
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to va... |
Moderate |
kernel |
否 |
完成修复 |
2021-01-07 |
2026-01-20 |
| CVE-2020-8265 |
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. Whe... |
Important |
nodejs, nodejs:20 |
否 |
完成修复 |
2021-01-06 |
2026-01-06 |
| CVE-2020-4761 |
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remo... |
Moderate |
kernel |
否 |
完成修复 |
2021-01-05 |
2025-12-23 |
| CVE-2020-27845 |
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted inpu... |
Low |
openjpeg2 |
是 |
完成修复 |
2021-01-05 |
2026-03-27 |
| CVE-2020-27843 |
A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the... |
Low |
openjpeg2 |
是 |
完成修复 |
2021-01-05 |
2026-03-27 |
| CVE-2020-27842 |
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be proc... |
Low |
openjpeg2 |
是 |
完成修复 |
2021-01-05 |
2026-03-27 |
| CVE-2019-4728 |
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remo... |
Important |
kernel |
否 |
完成修复 |
2021-01-05 |
2025-12-04 |
| CVE-2020-24386 |
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via a... |
Moderate |
dovecot |
是 |
完成修复 |
2021-01-04 |
2026-07-13 |
| CVE-2019-25013 |
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in... |
Moderate |
glibc |
否 |
完成修复 |
2021-01-04 |
2025-12-11 |
| CVE-2020-35963 |
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calcu... |
Moderate |
kernel |
否 |
完成修复 |
2021-01-03 |
2026-01-20 |
| CVE-2020-35654 |
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interp... |
Moderate |
python-pillow |
是 |
完成修复 |
2021-01-03 |
2026-03-23 |
| CVE-2021-20199 |
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). T... |
Moderate |
container-tools:2.0, podman, container-tools:an8, container-tools:1.0 |
是 |
完成修复 |
2021-01-01 |
2026-03-23 |
| CVE-2020-35702 |
DISPUTED DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF docume... |
Moderate |
poppler |
是 |
完成修复 |
2020-12-25 |
2026-03-27 |
| CVE-2020-27846 |
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The ... |
Critical |
grafana, grafana-pcp |
否 |
完成修复 |
2020-12-21 |
2026-01-10 |
| CVE-2020-29652 |
Go 语言的 golang.org/x/crypto/ssh 组件(版本 v0.0.0-20201203163018-be400aefbc4c)中存在空指针解引用漏洞,�... |
Important |
container-tools:an8, udica |
否 |
完成修复 |
2020-12-15 |
2025-12-29 |
| CVE-2020-29363 |
|
Moderate |
p11-kit |
是 |
完成修复 |
2020-12-11 |
2026-03-23 |
| CVE-2020-29362 |
|
Moderate |
p11-kit |
是 |
完成修复 |
2020-12-11 |
2026-03-23 |
| CVE-2020-29361 |
|
Moderate |
p11-kit |
是 |
完成修复 |
2020-12-11 |
2026-03-27 |
| CVE-2020-36242 |
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values... |
Important |
python-cryptography |
否 |
完成修复 |
2020-12-09 |
2025-12-30 |
| CVE-2020-8286 |
|
Moderate |
curl |
是 |
完成修复 |
2020-12-08 |
2026-03-23 |
| CVE-2020-8285 |
|
Moderate |
curl |
是 |
完成修复 |
2020-12-08 |
2026-03-23 |
| CVE-2020-8284 |
|
Moderate |
curl |
是 |
完成修复 |
2020-12-08 |
2026-03-23 |
| CVE-2020-28935 |
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local ... |
Moderate |
unbound |
是 |
完成修复 |
2020-12-07 |
2026-03-23 |
| CVE-2020-27821 |
QEMU(Quick Emulator)是法国法布里斯-贝拉(Fabrice Bellard)个人开发者的一套模拟处理器软件。该软... |
Moderate |
virt:an, libvirt |
否 |
完成修复 |
2020-12-02 |
2025-12-18 |
| CVE-2020-25712 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-11-30 |
2026-03-23 |
| CVE-2020-27828 |
|
Moderate |
jasper |
是 |
完成修复 |
2020-11-29 |
2026-03-27 |
| CVE-2020-13543 |
|
Moderate |
gdm, webkit2gtk3 |
是 |
完成修复 |
2020-11-29 |
2026-03-23 |
| CVE-2020-9983 |
|
Moderate |
gdm, webkit2gtk3 |
是 |
完成修复 |
2020-11-22 |
2026-03-23 |
| CVE-2020-9952 |
|
Moderate |
gnome-settings-daemon, webkit2gtk3 |
是 |
完成修复 |
2020-11-22 |
2026-03-23 |
| CVE-2020-9951 |
|
Moderate |
gdm, webkit2gtk3 |
是 |
完成修复 |
2020-11-22 |
2026-03-23 |
| CVE-2020-9948 |
|
Moderate |
gdm, webkit2gtk3 |
是 |
完成修复 |
2020-11-22 |
2026-03-23 |
| CVE-2020-13584 |
|
Moderate |
gdm, webkit2gtk3 |
是 |
完成修复 |
2020-11-22 |
2026-03-23 |
| CVE-2021-28210 |
An unlimited recursion in DxeCore in EDK II. \nA flaw was found in edk2. An unlimited recursion in DxeCore may allow an attacke... |
Important |
ovmf, edk2 |
否 |
完成修复 |
2020-11-19 |
2026-01-05 |
| CVE-2020-28366 |
Go before 1.14.12 and 1.15.x before 1.15.5 allows Code Injection. \nAn input validation vulnerability was found in Go. From a g... |
Important |
gcc, golang, go-toolset:an8 |
是 |
完成修复 |
2020-11-12 |
2025-12-10 |
| CVE-2020-28362 |
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. \nA flaw was found in the math/big package of Go's standar... |
Important |
gcc, grafana, gcc-toolset-10-gcc, container-tools:1.0, container-tools:2.0, go-toolset:an8, container-tools:an8, golang, grafana-pcp |
是 |
完成修复 |
2020-11-12 |
2025-12-10 |
| CVE-2020-28916 |
QEMU(Quick Emulator)是法国法布里斯-贝拉(Fabrice Bellard)个人开发者的一套模拟处理器软件。该软... |
Low |
virt:an, libvirt |
否 |
完成修复 |
2020-11-11 |
2025-12-18 |
| CVE-2020-16125 |
|
Low |
gdm |
否 |
完成修复 |
2020-11-09 |
2026-01-25 |
| CVE-2020-25653 |
|
Moderate |
spice-vdagent |
是 |
完成修复 |
2020-11-02 |
2026-03-30 |
| CVE-2020-25652 |
|
Low |
spice-vdagent |
是 |
完成修复 |
2020-11-02 |
2026-03-23 |
| CVE-2020-25651 |
|
Moderate |
spice-vdagent |
是 |
完成修复 |
2020-11-02 |
2026-03-30 |
| CVE-2020-25650 |
|
Low |
spice-vdagent |
是 |
完成修复 |
2020-11-02 |
2026-03-23 |
| CVE-2020-27216 |
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on ... |
Important |
jetty |
否 |
完成修复 |
2020-10-23 |
2026-01-06 |
| CVE-2020-15684 |
Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption a... |
Important |
firefox |
否 |
完成修复 |
2020-10-22 |
2026-01-04 |
| CVE-2020-14798 |
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are af... |
Low |
java-11-openjdk, java-1.8.0-openjdk |
否 |
完成修复 |
2020-10-21 |
2025-12-05 |
| CVE-2020-25692 |
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. A... |
Important |
compat-openldap, openldap |
否 |
完成修复 |
2020-10-19 |
2026-01-07 |
| CVE-2020-27783 |
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which c... |
Moderate |
python27:2.7, python-lxml |
是 |
完成修复 |
2020-10-18 |
2026-07-10 |
| CVE-2020-11979 |
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the curren... |
Moderate |
ant |
是 |
完成修复 |
2020-10-01 |
2026-03-23 |
| CVE-2020-25637 |
Red Hat libvirt是美国红帽(Red Hat)公司的一个用于实现Linux虚拟化功能的Linux API,它支持各种Hypervi... |
Moderate |
virt:an, libvirt |
否 |
完成修复 |
2020-09-29 |
2025-12-18 |
| CVE-2020-1968 |
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master ... |
Moderate |
compat-openssl10, openssl098e, openssl, ovmf, mingw-openssl |
是 |
完成修复 |
2020-09-09 |
2026-03-27 |
| CVE-2019-19499 |
|
Moderate |
grafana, grafana-pcp |
是 |
完成修复 |
2020-08-26 |
2026-03-27 |
| CVE-2020-14363 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-08-24 |
2026-07-11 |
| CVE-2020-14362 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-08-24 |
2026-03-23 |
| CVE-2020-14361 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-08-24 |
2026-03-23 |
| CVE-2020-14346 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-08-24 |
2026-03-23 |
| CVE-2020-14345 |
|
Moderate |
xorg-x11-server, libwacom |
是 |
完成修复 |
2020-08-24 |
2026-03-23 |
| CVE-2020-14364 |
QEMU 5.2.0 https://www.qemu.org/blog/2020/12/ 已经修复此漏洞 |
Important |
virt:an, qemu-kvm |
否 |
完成修复 |
2020-08-23 |
2025-12-05 |
| CVE-2020-8231 |
|
Low |
curl |
是 |
完成修复 |
2020-08-18 |
2026-03-23 |
| CVE-2020-1472 |
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to ... |
Critical |
openchange, samba |
否 |
完成修复 |
2020-08-17 |
2026-01-10 |
| CVE-2020-24332 |
|
Moderate |
trousers |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-24331 |
|
Moderate |
trousers |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-17538 |
|
Low |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16310 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16309 |
|
Low |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16308 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16307 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16306 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16305 |
|
Low |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16304 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16303 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16302 |
|
Low |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16301 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16300 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16299 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16298 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16297 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16296 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16295 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16294 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16293 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16292 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16291 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16290 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16289 |
|
Low |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-23 |
| CVE-2020-16288 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-16287 |
|
Moderate |
ghostscript |
是 |
完成修复 |
2020-08-12 |
2026-03-30 |
| CVE-2020-17507 |
|
Moderate |
qt5-qtbase |
是 |
完成修复 |
2020-08-11 |
2026-03-30 |
| CVE-2020-8025 |
A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUS... |
Moderate |
pcp |
是 |
完成修复 |
2020-08-07 |
2026-03-30 |
| CVE-2020-11993 |
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge pat... |
Moderate |
httpd:2.4, mod_http2 |
是 |
完成修复 |
2020-08-06 |
2026-07-10 |
| CVE-2020-11984 |
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
Moderate |
httpd:2.4, mod_http2 |
是 |
完成修复 |
2020-08-06 |
2026-07-10 |