| CVE-2019-7575 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audi... |
Moderate |
SDL |
是 |
完成修复 |
2019-02-05 |
2026-03-31 |
| CVE-2019-7573 |
|
Low |
SDL |
是 |
完成修复 |
2019-02-05 |
2026-03-30 |
| CVE-2019-7572 |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audi... |
Moderate |
SDL |
是 |
完成修复 |
2019-02-05 |
2026-03-31 |
| CVE-2018-16890 |
An out-of-bounds read flaw was found in the way curl handled NTLMv2 type-2 headers. When connecting to a remote malicious serve... |
Moderate |
curl |
是 |
完成修复 |
2019-02-05 |
2026-03-31 |
| CVE-2019-7576 |
|
Low |
SDL |
是 |
完成修复 |
2019-02-04 |
2026-03-30 |
| CVE-2018-16838 |
|
Low |
sssd |
是 |
完成修复 |
2019-02-03 |
2026-03-30 |
| CVE-2018-20749 |
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 ... |
Important |
libvncserver |
否 |
完成修复 |
2019-01-31 |
2026-01-05 |
| CVE-2018-18508 |
|
Moderate |
nss |
是 |
完成修复 |
2019-01-21 |
2026-03-31 |
| CVE-2018-17199 |
|
Moderate |
mod_http2, httpd:2.4 |
是 |
完成修复 |
2019-01-21 |
2026-07-10 |
| CVE-2019-9169 |
|
Moderate |
glibc |
否 |
完成修复 |
2019-01-19 |
2025-12-11 |
| CVE-2019-9003 |
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arran... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2019-01-16 |
2025-12-17 |
| CVE-2018-20721 |
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParseEx functions) for an incomplete URI ... |
Low |
uriparser |
否 |
完成修复 |
2019-01-16 |
2026-01-25 |
| CVE-2019-6978 |
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_w... |
Moderate |
libwmf, gd, php |
是 |
完成修复 |
2019-01-15 |
2026-07-11 |
| CVE-2019-2534 |
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are af... |
Important |
mariadb, mariadb:10.5, mysql:8.0, mariadb:10.3, mysql |
否 |
完成修复 |
2019-01-15 |
2026-01-04 |
| CVE-2019-6706 |
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who ... |
Important |
lua-rpm-macros |
否 |
完成修复 |
2019-01-10 |
2026-01-04 |
| CVE-2018-20622 |
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. |
Low |
jasper, netpbm |
是 |
完成修复 |
2018-12-31 |
2026-03-30 |
| CVE-2018-20662 |
|
Low |
poppler |
是 |
完成修复 |
2018-12-29 |
2026-03-30 |
| CVE-2018-20650 |
|
Low |
poppler |
是 |
完成修复 |
2018-12-27 |
2026-03-27 |
| CVE-2018-20673 |
binutils 2.31.1 合并的 libiberty 代码 (cplus-dem.c) 可能在特定输入目标文件的情况下产生缓冲区溢出问�... |
Low |
gcc |
否 |
完成修复 |
2018-12-26 |
2025-12-15 |
| CVE-2018-20551 |
|
Low |
poppler |
是 |
完成修复 |
2018-12-25 |
2026-03-27 |
| CVE-2018-20483 |
|
Low |
curl |
否 |
完成修复 |
2018-12-25 |
2026-01-25 |
| CVE-2018-20481 |
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denia... |
Low |
poppler |
是 |
完成修复 |
2018-12-19 |
2026-07-10 |
| CVE-2018-20657 |
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a ... |
Low |
gdb |
否 |
完成修复 |
2018-12-17 |
2025-12-09 |
| CVE-2018-20337 |
|
Moderate |
libvncserver, vinagre |
是 |
完成修复 |
2018-12-17 |
2026-07-11 |
| CVE-2018-20815 |
A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load a device tree blob ... |
Important |
qemu |
否 |
完成修复 |
2018-12-13 |
2025-12-10 |
| CVE-2018-19985 |
|
Low |
kernel |
否 |
完成修复 |
2018-12-11 |
2026-01-20 |
| CVE-2018-20099 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-12-09 |
2026-03-27 |
| CVE-2018-20098 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-12-09 |
2026-03-27 |
| CVE-2018-20097 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-12-09 |
2026-03-27 |
| CVE-2018-20096 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-12-09 |
2026-03-27 |
| CVE-2018-20169 |
|
Moderate |
kernel |
否 |
完成修复 |
2018-12-04 |
2025-12-23 |
| CVE-2018-19872 |
|
Moderate |
sip, qt5-qtbase |
是 |
完成修复 |
2018-12-03 |
2026-03-27 |
| CVE-2018-19824 |
|
Moderate |
kernel |
否 |
完成修复 |
2018-12-03 |
2025-12-23 |
| CVE-2018-18356 |
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote a... |
Important |
thunderbird |
否 |
完成修复 |
2018-12-03 |
2026-01-05 |
| CVE-2018-19519 |
|
Low |
tcpdump |
是 |
完成修复 |
2018-12-02 |
2026-03-27 |
| CVE-2018-16884 |
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time... |
Important |
kernel |
是 |
完成修复 |
2018-11-26 |
2025-12-04 |
| CVE-2018-12121 |
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using ... |
Moderate |
http-parser |
是 |
完成修复 |
2018-11-26 |
2026-03-31 |
| CVE-2018-1000858 |
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker ... |
Moderate |
gnupg2 |
是 |
完成修复 |
2018-11-22 |
2026-03-31 |
| CVE-2018-20534 |
|
Low |
microdnf, libdnf |
是 |
完成修复 |
2018-11-21 |
2026-03-27 |
| CVE-2018-1000878 |
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use Aft... |
Moderate |
libarchive |
是 |
完成修复 |
2018-11-19 |
2026-03-31 |
| CVE-2018-1000877 |
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double ... |
Moderate |
libarchive |
是 |
完成修复 |
2018-11-19 |
2026-03-31 |
| CVE-2018-19854 |
|
Moderate |
kernel |
否 |
完成修复 |
2018-11-02 |
2025-12-23 |
| CVE-2018-18897 |
|
Low |
poppler |
是 |
完成修复 |
2018-10-31 |
2026-03-27 |
| CVE-2018-18751 |
|
Low |
gettext |
是 |
完成修复 |
2018-10-27 |
2026-03-27 |
| CVE-2018-0735 |
|
Low |
openssl |
是 |
完成修复 |
2018-10-24 |
2026-03-27 |
| CVE-2018-10933 |
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could creat... |
Important |
libssh |
否 |
完成修复 |
2018-10-17 |
2026-01-08 |
| CVE-2018-0734 |
|
Low |
openssl |
是 |
完成修复 |
2018-10-15 |
2026-03-27 |
| CVE-2018-11784 |
|
Moderate |
pki-deps:10.6, xsom |
是 |
完成修复 |
2018-10-02 |
2026-07-10 |
| CVE-2018-17828 |
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip ... |
Moderate |
zziplib |
是 |
完成修复 |
2018-09-25 |
2026-07-13 |
| CVE-2018-21035 |
|
Moderate |
qt5-qtwebsockets, qt5-qtbase |
是 |
完成修复 |
2018-09-22 |
2026-03-27 |
| CVE-2018-25013 |
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ShiftBytes. The highest threa... |
Moderate |
libwebp |
是 |
完成修复 |
2018-08-20 |
2026-03-31 |
| CVE-2018-15471 |
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as use... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2018-08-14 |
2025-12-04 |
| CVE-2018-15518 |
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document. |
Moderate |
qt5-qttools |
是 |
完成修复 |
2018-08-12 |
2026-03-31 |
| CVE-2018-20677 |
|
Moderate |
softhsm, idm:DL1 |
是 |
完成修复 |
2018-08-09 |
2026-03-27 |
| CVE-2018-20676 |
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. |
Moderate |
softhsm, idm:DL1 |
是 |
完成修复 |
2018-08-09 |
2026-06-26 |
| CVE-2018-8037 |
If an async request was completed by the application at the same time as the container triggered the async timeout, a race cond... |
Important |
xsom, pki-deps:10.6 |
否 |
完成修复 |
2018-07-21 |
2026-01-04 |
| CVE-2018-8034 |
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affecte... |
Low |
xsom, pki-deps:10.6 |
是 |
完成修复 |
2018-07-21 |
2026-07-09 |
| CVE-2018-10896 |
|
Low |
cloud-init |
是 |
完成修复 |
2018-07-05 |
2026-07-09 |
| CVE-2017-18342 |
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has bee... |
Important |
PyYAML |
否 |
完成修复 |
2018-06-27 |
2026-01-04 |
| CVE-2018-12900 |
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4... |
Moderate |
libtiff |
是 |
完成修复 |
2018-06-25 |
2026-03-31 |
| CVE-2018-10871 |
|
Moderate |
389-ds-base, 389-ds:1.4 |
是 |
完成修复 |
2018-06-17 |
2026-07-13 |
| CVE-2018-11685 |
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. |
Moderate |
liblouis |
是 |
完成修复 |
2018-06-05 |
2026-03-31 |
| CVE-2018-11684 |
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. |
Moderate |
liblouis |
是 |
完成修复 |
2018-06-05 |
2026-03-31 |
| CVE-2018-12085 |
|
Low |
liblouis |
是 |
完成修复 |
2018-06-04 |
2026-03-27 |
| CVE-2018-11577 |
|
Low |
liblouis |
是 |
完成修复 |
2018-05-29 |
2026-03-27 |
| CVE-2018-14042 |
|
Moderate |
softhsm, tomcatjss, pki-deps:10.6 |
是 |
完成修复 |
2018-05-28 |
2026-03-27 |
| CVE-2018-14040 |
|
Moderate |
softhsm, tomcatjss, pki-deps:10.6 |
是 |
完成修复 |
2018-05-28 |
2026-03-20 |
| CVE-2018-15587 |
|
Moderate |
evolution-data-server, evolution-ews |
是 |
完成修复 |
2018-05-26 |
2026-07-11 |
| CVE-2018-14613 |
An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when ... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2018-05-26 |
2025-12-17 |
| CVE-2018-8014 |
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.... |
Moderate |
xsom, pki-deps:10.6 |
是 |
完成修复 |
2018-05-16 |
2026-07-10 |
| CVE-2018-10772 |
|
Low |
exiv2, libgexiv2 |
是 |
完成修复 |
2018-04-11 |
2026-03-27 |
| CVE-2018-9304 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-04-03 |
2026-03-27 |
| CVE-2018-9303 |
|
Low |
libgexiv2, exiv2 |
是 |
完成修复 |
2018-04-03 |
2026-03-20 |
| CVE-2019-16680 |
|
Moderate |
file-roller |
否 |
完成修复 |
2018-03-13 |
2026-01-25 |
| CVE-2018-7263 |
|
Low |
libmad, SDL2 |
是 |
完成修复 |
2018-02-19 |
2026-03-20 |
| CVE-2018-6616 |
|
Low |
openjpeg2 |
是 |
完成修复 |
2018-02-03 |
2026-03-20 |
| CVE-2018-5785 |
|
Low |
openjpeg2 |
是 |
完成修复 |
2018-01-18 |
2026-03-20 |
| CVE-2018-5727 |
In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attack... |
Low |
openjpeg2 |
是 |
完成修复 |
2018-01-12 |
2026-07-10 |
| CVE-2017-18216 |
In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users can cause a denial of service (NULL pointer dere... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2017-11-16 |
2025-12-17 |
| CVE-2017-14503 |
|
Low |
libarchive |
是 |
完成修复 |
2017-09-15 |
2026-03-27 |
| CVE-2017-14502 |
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR a... |
Moderate |
libarchive |
是 |
完成修复 |
2017-09-15 |
2026-03-31 |
| CVE-2017-14501 |
|
Low |
libarchive |
是 |
完成修复 |
2017-09-15 |
2026-03-20 |
| CVE-2017-14166 |
|
Low |
libarchive |
是 |
完成修复 |
2017-09-04 |
2026-03-27 |
| CVE-2017-18926 |
|
Moderate |
raptor2 |
是 |
完成修复 |
2017-06-06 |
2026-03-26 |
| CVE-2016-10228 |
https://sourceware.org/bugzilla/show_bug.cgi?id=19519 \n |
Low |
glibc |
否 |
完成修复 |
2017-01-24 |
2025-12-11 |
| CVE-2016-10745 |
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape. \nA flaw was found in Pallets Jinja prior to version 2.8.1 a... |
Important |
python27:2.7, python-jinja2 |
否 |
完成修复 |
2016-12-29 |
2026-01-04 |
| CVE-2016-10735 |
|
Moderate |
pki-deps:10.6, tomcatjss, softhsm |
是 |
完成修复 |
2016-06-26 |
2026-03-20 |
| CVE-2015-9541 |
|
Moderate |
qt5-qtwebsockets, qt5-qtbase |
是 |
完成修复 |
2015-07-23 |
2026-03-19 |
| CVE-2015-3416 |
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floa... |
Moderate |
sqlite |
否 |
完成修复 |
2015-03-31 |
2026-01-25 |
| CVE-2025-66034 |
fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLi... |
Moderate |
fonttools |
是 |
完成修复 |
2025-12-01 |
2026-07-11 |
| CVE-2025-61915 |
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a... |
Moderate |
cups |
是 |
完成修复 |
2025-12-01 |
2026-03-31 |
| CVE-2025-58436 |
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a... |
Moderate |
cups |
是 |
完成修复 |
2025-12-01 |
2026-03-31 |
| CVE-2025-58188 |
Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes t... |
Moderate |
golang |
是 |
完成修复 |
2025-12-01 |
2025-12-10 |
| CVE-2025-55160 |
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and ... |
Moderate |
ImageMagick |
是 |
完成修复 |
2025-12-01 |
2026-03-31 |
| CVE-2025-13699 |
A flaw was found in MariaDB. This vulnerability allows remote attackers to execute arbitrary code on affected installations via... |
Important |
mariadb:10.5, mariadb, mariadb:10.3 |
是 |
完成修复 |
2025-12-01 |
2025-12-29 |
| CVE-2025-2486 |
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly... |
Low |
edk2 |
否 |
完成修复 |
2025-11-28 |
2026-01-25 |
| CVE-2025-13674 |
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service |
Moderate |
wireshark |
是 |
完成修复 |
2025-11-27 |
2026-03-26 |
| CVE-2025-13601 |
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_stri... |
Moderate |
mingw-glib2, glib2 |
是 |
完成修复 |
2025-11-27 |
2026-07-10 |
| CVE-2025-47913 |
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client pr... |
Important |
golang |
是 |
完成修复 |
2025-11-26 |
2025-12-10 |
| CVE-2025-13502 |
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to... |
Important |
webkit2gtk3, webkitgtk |
是 |
完成修复 |
2025-11-26 |
2026-01-04 |