| CVE-2019-16865 |
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allo... |
Important |
python-pillow |
否 |
完成修复 |
2019-10-04 |
2026-01-04 |
| CVE-2019-16866 |
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query... |
Moderate |
unbound |
否 |
完成修复 |
2019-10-03 |
2026-01-25 |
| CVE-2018-16452 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16451 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16300 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16230 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16229 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16228 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-16227 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14882 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14881 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14880 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14879 |
|
Moderate |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14470 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14469 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14468 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14467 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14466 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14465 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14464 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14463 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14462 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2018-14461 |
|
Low |
tcpdump |
否 |
完成修复 |
2019-10-01 |
2026-01-25 |
| CVE-2019-16276 |
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. \nIt was discovered that net/http (through net/textpro... |
Moderate |
gcc, golang, go-toolset:an8 |
是 |
完成修复 |
2019-09-25 |
2025-12-10 |
| CVE-2019-3689 |
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterpris... |
Moderate |
nfs-utils |
是 |
完成修复 |
2019-09-19 |
2026-03-30 |
| CVE-2019-20382 |
在ui/ VNC断开操作期间,QEMU 4.1.0在zrle_compress_data中的zrle_compress_data中存在内存泄漏,因为libz被滥�... |
Low |
libvirt, virt:an |
否 |
完成修复 |
2019-09-16 |
2025-12-18 |
| CVE-2019-18277 |
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" v... |
Moderate |
haproxy |
否 |
完成修复 |
2019-09-13 |
2026-01-25 |
| CVE-2019-1549 |
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a f... |
Moderate |
openssl, mingw-openssl |
是 |
完成修复 |
2019-09-10 |
2026-03-30 |
| CVE-2019-10214 |
|
Moderate |
toolbox, slirp4netns, container-tools:1.0 |
是 |
完成修复 |
2019-09-08 |
2026-03-30 |
| CVE-2019-15927 |
An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_procunit ... |
Important |
kernel:5.10, kernel:4.19, kernel:6.6 |
是 |
完成修复 |
2019-09-04 |
2025-12-04 |
| CVE-2019-15919 |
An issue was discovered in the Linux kernel before 5.0.10. SMB2_write in fs/cifs/smb2pdu.c has a use-after-free. |
Important |
kernel:5.10, kernel:4.19, kernel:6.6 |
是 |
完成修复 |
2019-09-04 |
2025-12-04 |
| CVE-2019-15903 |
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early;... |
Important |
firefox, python, expat, thunderbird, cmake, python3, python27:2.7 |
否 |
完成修复 |
2019-09-04 |
2026-01-09 |
| CVE-2019-12402 |
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when fac... |
Important |
apache-commons-compress |
否 |
完成修复 |
2019-08-30 |
2026-01-06 |
| CVE-2019-14866 |
|
Moderate |
cpio |
否 |
完成修复 |
2019-08-29 |
2026-01-25 |
| CVE-2018-20969 |
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same co... |
Important |
patch |
否 |
完成修复 |
2019-08-15 |
2025-12-29 |
| CVE-2019-17546 |
|
Moderate |
libtiff |
是 |
完成修复 |
2019-08-14 |
2026-03-30 |
| CVE-2019-14809 |
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in... |
Important |
golang, go-toolset:an8 |
是 |
完成修复 |
2019-08-13 |
2025-12-10 |
| CVE-2019-10097 |
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PRO... |
Moderate |
httpd:2.4, mod_md |
是 |
完成修复 |
2019-08-13 |
2026-07-10 |
| CVE-2019-10082 |
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after... |
Moderate |
httpd:2.4, mod_md |
是 |
完成修复 |
2019-08-13 |
2026-07-10 |
| CVE-2019-10081 |
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of m... |
Moderate |
httpd:2.4, mod_md |
是 |
完成修复 |
2019-08-13 |
2026-07-10 |
| CVE-2019-14806 |
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share... |
Important |
python-werkzeug |
否 |
完成修复 |
2019-08-09 |
2026-01-04 |
| CVE-2019-14234 |
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallo... |
Moderate |
mupdf |
是 |
完成修复 |
2019-08-09 |
2026-03-30 |
| CVE-2019-14271 |
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facil... |
Important |
docker |
否 |
完成修复 |
2019-07-29 |
2026-01-08 |
| CVE-2019-14378 |
|
Important |
toolbox, container-tools:1.0, slirp4netns |
否 |
完成修复 |
2019-07-27 |
2025-12-30 |
| CVE-2019-9959 |
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an In... |
Moderate |
evince, poppler-data |
是 |
完成修复 |
2019-07-23 |
2026-03-30 |
| CVE-2019-17543 |
LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications tha... |
Important |
lz4 |
否 |
完成修复 |
2019-07-17 |
2026-01-09 |
| CVE-2018-14550 |
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the f... |
Important |
libpng |
否 |
完成修复 |
2019-07-10 |
2026-01-05 |
| CVE-2017-12652 |
libpng before 1.6.32 does not properly check the length of chunks against the user limit. |
Low |
libpng |
否 |
完成修复 |
2019-07-10 |
2026-01-25 |
| CVE-2019-18276 |
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its e... |
Important |
bash, bash-completion |
否 |
完成修复 |
2019-07-01 |
2026-01-07 |
| CVE-2019-13050 |
|
Moderate |
gnupg2 |
是 |
完成修复 |
2019-06-28 |
2026-03-31 |
| CVE-2021-4214 |
A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a... |
Moderate |
libpng |
是 |
完成修复 |
2019-06-25 |
2026-03-31 |
| CVE-2019-12973 |
|
Low |
openjpeg2 |
是 |
完成修复 |
2019-06-25 |
2026-03-30 |
| CVE-2018-20847 |
|
Low |
openjpeg2 |
是 |
完成修复 |
2019-06-25 |
2026-03-30 |
| CVE-2018-20845 |
|
Low |
openjpeg2 |
是 |
完成修复 |
2019-06-25 |
2026-03-30 |
| CVE-2018-20843 |
|
Moderate |
expat, mingw-expat |
是 |
完成修复 |
2019-06-23 |
2026-03-27 |
| CVE-2019-10747 |
|
Low |
nodejs, nodejs-nodemon, nodejs:12 |
是 |
完成修复 |
2019-06-19 |
2026-03-30 |
| CVE-2019-10168 |
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs accept an "emulator" argument to specif... |
Important |
libvirt |
否 |
完成修复 |
2019-06-19 |
2025-12-09 |
| CVE-2019-10167 |
The virConnectGetDomainCapabilities() libvirt API accepts an "emulatorbin" argument to specify the program providing emulation ... |
Important |
libvirt |
否 |
完成修复 |
2019-06-19 |
2025-12-09 |
| CVE-2019-10166 |
It was discovered that libvirtd would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permi... |
Important |
libvrit |
否 |
完成修复 |
2019-06-19 |
2025-12-09 |
| CVE-2019-10161 |
我们发现libvirtd将允许只读客户端使用virDomainSaveImageGetXMLDesc() API,指定一个任意路径,该路径将�... |
Important |
libvirt |
是 |
完成修复 |
2019-06-19 |
2025-12-09 |
| CVE-2019-8324 |
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly.... |
Important |
ruby, ruby:2.5 |
否 |
完成修复 |
2019-06-17 |
2026-01-04 |
| CVE-2018-16871 |
|
Moderate |
kernel |
否 |
完成修复 |
2019-06-02 |
2025-12-23 |
| CVE-2019-10132 |
A flaw was found in libvirt in version 4.1.0 and earlier. A missing SocketMode configuration parameter allows any user on the h... |
Important |
libvirt, virt:an |
否 |
完成修复 |
2019-05-20 |
2025-12-09 |
| CVE-2019-13173 |
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that alrea... |
Important |
nodejs, nodejs:20, nodejs:10 |
否 |
完成修复 |
2019-05-15 |
2026-01-06 |
| CVE-2018-12130 |
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may ... |
Important |
virt:an, virt-v2v, kernel |
是 |
完成修复 |
2019-05-13 |
2025-12-04 |
| CVE-2018-12127 |
Microprocessor使用“加载端口”子组件从内存或IO执行加载操作。在加载操作期间,加载端口�... |
Moderate |
virt:an, virt-v2v, kernel |
否 |
完成修复 |
2019-05-13 |
2025-12-18 |
| CVE-2018-12126 |
现代英特尔微处理器实现了硬件级的微优化,以提高向CPU缓存写入数据的性能。写入操作被分成S... |
Moderate |
virt:an, virt-v2v, kernel |
否 |
完成修复 |
2019-05-13 |
2025-12-18 |
| CVE-2019-5018 |
|
Moderate |
sqlite |
是 |
完成修复 |
2019-05-08 |
2026-03-31 |
| CVE-2019-11811 |
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports... |
Important |
kernel:5.10, kernel:4.19, kernel:6.6 |
是 |
完成修复 |
2019-05-07 |
2025-12-04 |
| CVE-2019-5827 |
|
Moderate |
sqlite |
是 |
完成修复 |
2019-04-29 |
2026-03-31 |
| CVE-2019-12155 |
qxl: check release info object \n \n When releasing spice resources in release_resource() routine, \n if release ... |
Low |
virt:an, sgabios |
否 |
完成修复 |
2019-04-24 |
2025-12-18 |
| CVE-2018-16878 |
|
Moderate |
pacemaker |
是 |
完成修复 |
2019-04-16 |
2026-03-31 |
| CVE-2018-16877 |
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A l... |
Important |
pacemaker |
否 |
完成修复 |
2019-04-16 |
2026-01-05 |
| CVE-2019-11068 |
|
Moderate |
libxslt |
是 |
完成修复 |
2019-04-09 |
2026-03-30 |
| CVE-2019-0217 |
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could... |
Moderate |
httpd:2.4, mod_md |
是 |
完成修复 |
2019-03-31 |
2026-07-10 |
| CVE-2019-0215 |
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification ... |
Important |
httpd:2.4, mod_md |
否 |
完成修复 |
2019-03-31 |
2026-01-09 |
| CVE-2019-0211 |
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child... |
Important |
httpd:2.4, mod_md |
否 |
完成修复 |
2019-03-31 |
2026-01-09 |
| CVE-2019-9946 |
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration whi... |
Moderate |
toolbox, container-tools:an8 |
是 |
完成修复 |
2019-03-27 |
2026-06-26 |
| CVE-2019-11358 |
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Ob... |
Moderate |
pcs, tomcatjss, softhsm |
是 |
完成修复 |
2019-03-27 |
2026-07-09 |
| CVE-2018-18506 |
|
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2019-03-19 |
2026-01-24 |
| CVE-2019-3833 |
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially c... |
Important |
openwsman |
否 |
完成修复 |
2019-03-14 |
2026-01-05 |
| CVE-2019-9741 |
|
Moderate |
golang, go-toolset:an8 |
是 |
完成修复 |
2019-03-12 |
2025-12-10 |
| CVE-2019-3863 |
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboa... |
Important |
libssh2 |
否 |
完成修复 |
2019-03-12 |
2026-01-04 |
| CVE-2019-3857 |
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_C... |
Important |
libssh2 |
否 |
完成修复 |
2019-03-12 |
2026-01-04 |
| CVE-2019-3856 |
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboar... |
Important |
libssh2 |
否 |
完成修复 |
2019-03-12 |
2026-01-04 |
| CVE-2019-3855 |
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets a... |
Important |
libssh2 |
否 |
完成修复 |
2019-03-12 |
2026-01-04 |
| CVE-2019-9631 |
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. |
Moderate |
poppler-data |
是 |
完成修复 |
2019-03-07 |
2026-03-31 |
| CVE-2018-12181 |
A stack-based buffer overflow was discovered in edk2 when the HII database contains a Bitmap that claims to be 4-bit or 8-bit p... |
Moderate |
edk2 |
是 |
完成修复 |
2019-03-06 |
2026-03-31 |
| CVE-2018-5745 |
|
Low |
bind |
是 |
完成修复 |
2019-02-20 |
2026-03-30 |
| CVE-2019-3890 |
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this fla... |
Important |
evolution-data-server, atkmm, evolution-mapi, evolution-ews |
否 |
完成修复 |
2019-02-15 |
2026-01-07 |
| CVE-2018-18509 |
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital sign... |
Moderate |
thunderbird |
是 |
完成修复 |
2019-02-13 |
2026-06-26 |
| CVE-2018-18511 |
|
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2019-02-11 |
2026-01-24 |
| CVE-2019-8331 |
|
Moderate |
pki-deps:10.6, tomcatjss, softhsm |
是 |
完成修复 |
2019-02-10 |
2026-03-30 |
| CVE-2019-7638 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_p... |
Moderate |
SDL |
是 |
完成修复 |
2019-02-07 |
2026-03-31 |
| CVE-2019-7637 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/S... |
Moderate |
SDL |
是 |
完成修复 |
2019-02-06 |
2026-03-31 |
| CVE-2019-7636 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/S... |
Moderate |
SDL |
是 |
完成修复 |
2019-02-06 |
2026-03-31 |
| CVE-2019-7635 |
|
Low |
SDL |
是 |
完成修复 |
2019-02-06 |
2026-03-30 |
| CVE-2019-7574 |
|
Low |
SDL |
是 |
完成修复 |
2019-02-06 |
2026-03-30 |
| CVE-2019-7578 |
|
Low |
SDL |
是 |
完成修复 |
2019-02-05 |
2026-03-30 |
| CVE-2019-7577 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.... |
Low |
SDL |
是 |
完成修复 |
2019-02-05 |
2026-07-10 |