| CVE-2025-37916 |
In the Linux kernel, the following vulnerability has been resolved: \npds_core: remove write-after-free of client_id \nA use-af... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2025-12-31 |
| CVE-2025-37910 |
In the Linux kernel, the following vulnerability has been resolved:\nptp: ocp: Fix NULL dereference in Adva board SMA sysfs ope... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2025-37764 |
In the Linux kernel, the following vulnerability has been resolved:\ndrm/imagination: fix firmware memory leaks\nFree the memor... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2025-23152 |
In the Linux kernel, the following vulnerability has been resolved:\narm64/crc-t10dif: fix use of out-of-scope array in crc_t10... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2023-53141 |
In the Linux kernel, the following vulnerability has been resolved:\nila: do not generate empty messages in ila_xlat_nl_cmd_get... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2023-53138 |
In the Linux kernel, the following vulnerability has been resolved:\nnet: caif: Fix use-after-free in cfusbl_device_notify()\ns... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2023-53061 |
In the Linux kernel, the following vulnerability has been resolved:\nksmbd: fix possible refcount leak in smb2_open()\nReferenc... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2023-53045 |
In the Linux kernel, the following vulnerability has been resolved:\nusb: gadget: u_audio: don't let userspace block driver unb... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-30 |
| CVE-2022-49836 |
In the Linux kernel, the following vulnerability has been resolved:\nsiox: fix possible memory leak in siox_device_add()\nIf de... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-31 |
| CVE-2022-49793 |
In the Linux kernel, the following vulnerability has been resolved:\niio: trigger: sysfs: fix possible memory leak in iio_sysfs... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-17 |
2026-01-31 |
| CVE-2025-40915 |
Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. \n \nThat version of the m... |
Important |
perl-Mojolicious |
否 |
完成修复 |
2025-06-16 |
2026-01-04 |
| CVE-2025-30167 |
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0... |
Important |
jupyterlab |
否 |
完成修复 |
2025-06-16 |
2026-01-06 |
| CVE-2024-9506 |
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability... |
Low |
firefox, thunderbird |
否 |
完成修复 |
2025-06-16 |
2026-01-20 |
| CVE-2024-48424 |
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp librar... |
Moderate |
qt5-qt3d |
是 |
完成修复 |
2025-06-16 |
2026-03-19 |
| CVE-2024-47831 |
Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 conta... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2025-06-16 |
2025-12-29 |
| CVE-2024-21272 |
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affec... |
Important |
mysql |
否 |
完成修复 |
2025-06-16 |
2026-01-10 |
| CVE-2022-35948 |
undici is an HTTP/1.1 client, written from scratch for Node.js.=< undici@5.8.0 users are vulnerable to CRLF Injection on he... |
Moderate |
nodejs |
是 |
完成修复 |
2025-06-16 |
2026-03-19 |
| CVE-2021-36374 |
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts o... |
Moderate |
ant |
是 |
完成修复 |
2025-06-16 |
2026-03-19 |
| CVE-2020-1945 |
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.... |
Moderate |
ant, ant:1.10, javapackages-tools:201801 |
是 |
完成修复 |
2025-06-16 |
2026-03-19 |
| CVE-2020-13935 |
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36... |
Important |
tomcat |
否 |
完成修复 |
2025-06-16 |
2026-01-04 |
| CVE-2020-13934 |
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HT... |
Important |
tomcat |
否 |
完成修复 |
2025-06-16 |
2026-01-04 |
| CVE-2020-11996 |
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8... |
Important |
tomcat |
是 |
完成修复 |
2025-06-16 |
2026-01-04 |
| CVE-2020-10177 |
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. |
Moderate |
python-pillow |
是 |
完成修复 |
2025-06-16 |
2026-03-19 |
| CVE-2014-4322 |
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android con... |
Moderate |
kernel |
是 |
完成修复 |
2025-06-16 |
2026-01-23 |
| CVE-2025-22874 |
No description is available for this CVE. |
Important |
golang, go-toolset:an8 |
是 |
完成修复 |
2025-06-13 |
2025-12-17 |
| CVE-2019-10247 |
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and J... |
Moderate |
jetty, eclipse:an8 |
是 |
完成修复 |
2025-06-13 |
2026-07-09 |
| CVE-2019-10241 |
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions i... |
Moderate |
jetty |
是 |
完成修复 |
2025-06-13 |
2026-07-09 |
| CVE-2025-6021 |
No description is available for this CVE. |
Moderate |
libxml2 |
是 |
完成修复 |
2025-06-12 |
2026-07-11 |
| CVE-2025-5991 |
A use-after-free vulnerability has been discovered in Qt's QHttp2ProtocolHandler function. This vulnerability only affects HTTP... |
Moderate |
qt5 |
是 |
完成修复 |
2025-06-12 |
2026-03-19 |
| CVE-2025-5601 |
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafte... |
Moderate |
wireshark |
否 |
完成修复 |
2025-06-12 |
2026-01-22 |
| CVE-2025-49796 |
No description is available for this CVE. |
Important |
libxml2 |
是 |
完成修复 |
2025-06-12 |
2026-01-04 |
| CVE-2025-49795 |
A null pointer dereference vulnerability was discovered in the libxml2. The issue occurs in the xmlSchematronFormatReport funct... |
Important |
libxml2 |
是 |
完成修复 |
2025-06-12 |
2026-01-04 |
| CVE-2025-49794 |
No description is available for this CVE. |
Important |
libxml2 |
是 |
完成修复 |
2025-06-12 |
2026-01-04 |
| CVE-2025-49710 |
An integer overflow was present in OrderedHashTable used by the JavaScript engine This vulnerability affects Firefox < 139.0.... |
Important |
firefox |
否 |
完成修复 |
2025-06-11 |
2025-12-29 |
| CVE-2025-49709 |
Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4. |
Important |
firefox |
否 |
完成修复 |
2025-06-11 |
2025-12-29 |
| CVE-2025-30348 |
encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a st... |
Moderate |
qt |
是 |
完成修复 |
2025-06-11 |
2026-07-10 |
| CVE-2024-48426 |
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing ... |
Moderate |
qt5-qt3d |
是 |
完成修复 |
2025-06-11 |
2026-03-19 |
| CVE-2024-47081 |
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third ... |
Moderate |
python-requests, python3.11-pip, python-pip, python39:3.9, fence-agents, python27:2.7, resource-agents |
是 |
完成修复 |
2025-06-11 |
2026-06-24 |
| CVE-2025-5683 |
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from v... |
Moderate |
qt5 |
是 |
完成修复 |
2025-06-10 |
2026-03-19 |
| CVE-2025-5399 |
Due to a mistake in libcurl's WebSocket code, a malicious server can send a\nparticularly crafted packet which makes libcurl ge... |
Moderate |
curl |
是 |
完成修复 |
2025-06-10 |
2026-03-19 |
| CVE-2019-5747 |
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, serv... |
Low |
busybox |
是 |
完成修复 |
2025-06-10 |
2026-03-19 |
| CVE-2018-20679 |
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, clien... |
Low |
busybox |
否 |
完成修复 |
2025-06-10 |
2026-01-22 |
| CVE-2025-29787 |
zip is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of af... |
Important |
zip |
否 |
完成修复 |
2025-06-09 |
2026-01-04 |
| CVE-2025-22870 |
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO... |
Moderate |
grafana, weldr-client, containernetworking-plugins, osbuild-composer, git-lfs, rhc, golang, grafana-pcp |
是 |
完成修复 |
2025-06-09 |
2025-12-11 |
| CVE-2024-8235 |
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case ... |
Moderate |
libvirt |
否 |
完成修复 |
2025-06-09 |
2025-12-18 |
| CVE-2024-51988 |
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API... |
Moderate |
rabbitmq-server |
是 |
完成修复 |
2025-06-09 |
2026-07-10 |
| CVE-2024-45306 |
Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a ... |
Moderate |
vim |
否 |
完成修复 |
2025-06-09 |
2026-01-22 |
| CVE-2024-45231 |
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used... |
Moderate |
python-django |
是 |
完成修复 |
2025-06-09 |
2026-03-19 |
| CVE-2024-39695 |
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An o... |
Moderate |
exiv2 |
是 |
完成修复 |
2025-06-09 |
2026-07-11 |
| CVE-2024-32228 |
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. |
Moderate |
ffmpeg |
否 |
完成修复 |
2025-06-09 |
2025-12-06 |
| CVE-2024-25112 |
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A de... |
Moderate |
exiv2 |
是 |
完成修复 |
2025-06-09 |
2026-07-11 |
| CVE-2024-24826 |
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An o... |
Moderate |
exiv2 |
否 |
完成修复 |
2025-06-09 |
2026-01-22 |
| CVE-2024-24787 |
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due... |
Moderate |
golang |
是 |
完成修复 |
2025-06-09 |
2025-12-11 |
| CVE-2024-22420 |
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architect... |
Moderate |
jupyterlab |
否 |
完成修复 |
2025-06-09 |
2026-01-22 |
| CVE-2024-21733 |
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: f... |
Moderate |
tomcat |
是 |
完成修复 |
2025-06-09 |
2026-06-26 |
| CVE-2023-40403 |
A flaw was found in libxslt package. Processing web content may disclose sensitive information. This issue was addressed with i... |
Moderate |
libxslt |
是 |
完成修复 |
2025-06-09 |
2026-03-19 |
| CVE-2022-49800 |
In the Linux kernel, the following vulnerability has been resolved:\ntracing: Fix memory leak in testgen_synth_cmd() and test... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-06-07 |
2026-01-30 |
| CVE-2025-5745 |
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector reg... |
Important |
glibc |
否 |
完成修复 |
2025-06-06 |
2025-12-11 |
| CVE-2025-5702 |
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector regi... |
Important |
glibc |
否 |
完成修复 |
2025-06-06 |
2025-12-11 |
| CVE-2023-5680 |
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database... |
Moderate |
bind9.16, bind |
是 |
完成修复 |
2025-06-06 |
2026-07-11 |
| CVE-2023-5568 |
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vuln... |
Moderate |
samba |
是 |
完成修复 |
2025-06-06 |
2026-07-09 |
| CVE-2023-48733 |
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypas... |
Moderate |
edk2 |
是 |
完成修复 |
2025-06-06 |
2026-03-19 |
| CVE-2023-47641 |
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vu... |
Moderate |
python-aiohttp |
是 |
完成修复 |
2025-06-06 |
2026-06-24 |
| CVE-2023-43490 |
Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privil... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-06-06 |
2026-07-10 |
| CVE-2023-40030 |
Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo... |
Moderate |
rust |
否 |
完成修复 |
2025-06-06 |
2025-12-16 |
| CVE-2023-39368 |
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentiall... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-06-06 |
2026-07-10 |
| CVE-2023-38575 |
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user t... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-06-06 |
2026-07-10 |
| CVE-2023-22313 |
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potent... |
Low |
qatlib |
是 |
完成修复 |
2025-06-06 |
2026-07-10 |
| CVE-2011-10007 |
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when grep() encounters a crafted filename. A... |
Important |
perl-File-Find-Rule-Perl, perl-File-Find-Rule |
否 |
完成修复 |
2025-06-06 |
2025-12-29 |
| CVE-2025-4435 |
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be... |
Important |
python3.11, python3, python39:3.9, python, python36:3.6 |
否 |
完成修复 |
2025-06-05 |
2025-12-29 |
| CVE-2025-4330 |
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modifi... |
Important |
python3.11, python3, python39:3.9, python, python36:3.6 |
否 |
完成修复 |
2025-06-05 |
2026-01-08 |
| CVE-2025-4138 |
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modifi... |
Important |
python3.11, python3, python39:3.9, python, python36:3.6 |
否 |
完成修复 |
2025-06-05 |
2026-01-08 |
| CVE-2025-27796 |
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to ... |
Moderate |
GraphicsMagick |
是 |
完成修复 |
2025-06-05 |
2026-07-11 |
| CVE-2025-27795 |
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. |
Moderate |
GraphicsMagick |
是 |
完成修复 |
2025-06-05 |
2026-07-11 |
| CVE-2023-49082 |
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an at... |
Moderate |
python-aiohttp |
是 |
完成修复 |
2025-06-05 |
2026-06-25 |
| CVE-2023-46445 |
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle at... |
Moderate |
python-asyncssh |
是 |
完成修复 |
2025-06-05 |
2026-06-25 |
| CVE-2023-46407 |
FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_v... |
Moderate |
ffmpeg |
否 |
完成修复 |
2025-06-05 |
2025-12-06 |
| CVE-2023-39978 |
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw. |
Low |
ImageMagick |
否 |
完成修复 |
2025-06-05 |
2026-01-22 |
| CVE-2023-3745 |
A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may all... |
Moderate |
ImageMagick |
是 |
完成修复 |
2025-06-05 |
2026-03-19 |
| CVE-2023-0809 |
In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets. |
Moderate |
mosquitto |
否 |
完成修复 |
2025-06-05 |
2026-01-22 |
| CVE-2025-48734 |
Improper Access Control vulnerability in Apache Commons. \n \n \n \nA special BeanIntrospector class was added in version 1.9.2... |
Important |
javapackages-tools:201801, apache-commons-beanutils |
否 |
完成修复 |
2025-06-04 |
2026-01-06 |
| CVE-2024-6614 |
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vuln... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2024-6610 |
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent ... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2024-6600 |
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating ... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2023-37210 |
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2023-37206 |
Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicio... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2023-37205 |
The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2023-37204 |
A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive comput... |
Moderate |
firefox |
否 |
完成修复 |
2025-06-04 |
2026-01-20 |
| CVE-2022-47952 |
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even wi... |
Low |
lxc |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2022-3647 |
DISPUTED A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the func... |
Low |
redis, redis:6, redis:5 |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2022-29869 |
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but... |
Moderate |
cifs-utils |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2021-45832 |
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (... |
Moderate |
hdf5 |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2021-40266 |
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference. |
Moderate |
freeimage |
是 |
完成修复 |
2025-06-04 |
2026-07-11 |
| CVE-2021-40264 |
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp. |
Moderate |
freeimage |
是 |
完成修复 |
2025-06-04 |
2026-07-11 |
| CVE-2021-40262 |
A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp. |
Moderate |
freeimage |
是 |
完成修复 |
2025-06-04 |
2026-07-11 |
| CVE-2021-3997 |
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when to... |
Moderate |
systemd |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2021-28429 |
Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attacke... |
Moderate |
ffmpeg |
否 |
完成修复 |
2025-06-04 |
2025-12-06 |
| CVE-2021-0127 |
Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-06-04 |
2026-07-10 |
| CVE-2020-26683 |
A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive inf... |
Moderate |
mupdf |
是 |
完成修复 |
2025-06-04 |
2026-03-19 |
| CVE-2020-21490 |
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory o... |
Moderate |
binutils |
否 |
完成修复 |
2025-06-04 |
2025-12-11 |