CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2025-37916 In the Linux kernel, the following vulnerability has been resolved: \npds_core: remove write-after-free of client_id \nA use-af... Important kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2025-12-31
CVE-2025-37910 In the Linux kernel, the following vulnerability has been resolved:\nptp: ocp: Fix NULL dereference in Adva board SMA sysfs ope... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2025-37764 In the Linux kernel, the following vulnerability has been resolved:\ndrm/imagination: fix firmware memory leaks\nFree the memor... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2025-23152 In the Linux kernel, the following vulnerability has been resolved:\narm64/crc-t10dif: fix use of out-of-scope array in crc_t10... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2023-53141 In the Linux kernel, the following vulnerability has been resolved:\nila: do not generate empty messages in ila_xlat_nl_cmd_get... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2023-53138 In the Linux kernel, the following vulnerability has been resolved:\nnet: caif: Fix use-after-free in cfusbl_device_notify()\ns... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2023-53061 In the Linux kernel, the following vulnerability has been resolved:\nksmbd: fix possible refcount leak in smb2_open()\nReferenc... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2023-53045 In the Linux kernel, the following vulnerability has been resolved:\nusb: gadget: u_audio: don't let userspace block driver unb... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-30
CVE-2022-49836 In the Linux kernel, the following vulnerability has been resolved:\nsiox: fix possible memory leak in siox_device_add()\nIf de... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-31
CVE-2022-49793 In the Linux kernel, the following vulnerability has been resolved:\niio: trigger: sysfs: fix possible memory leak in iio_sysfs... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-17 2026-01-31
CVE-2025-40915 Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. \n \nThat version of the m... Important perl-Mojolicious 完成修复 2025-06-16 2026-01-04
CVE-2025-30167 Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0... Important jupyterlab 完成修复 2025-06-16 2026-01-06
CVE-2024-9506 Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability... Low firefox, thunderbird 完成修复 2025-06-16 2026-01-20
CVE-2024-48424 A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp librar... Moderate qt5-qt3d 完成修复 2025-06-16 2026-03-19
CVE-2024-47831 Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 conta... Important firefox, thunderbird 完成修复 2025-06-16 2025-12-29
CVE-2024-21272 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affec... Important mysql 完成修复 2025-06-16 2026-01-10
CVE-2022-35948 undici is an HTTP/1.1 client, written from scratch for Node.js.=< undici@5.8.0 users are vulnerable to CRLF Injection on he... Moderate nodejs 完成修复 2025-06-16 2026-03-19
CVE-2021-36374 When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts o... Moderate ant 完成修复 2025-06-16 2026-03-19
CVE-2020-1945 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.... Moderate ant, ant:1.10, javapackages-tools:201801 完成修复 2025-06-16 2026-03-19
CVE-2020-13935 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36... Important tomcat 完成修复 2025-06-16 2026-01-04
CVE-2020-13934 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HT... Important tomcat 完成修复 2025-06-16 2026-01-04
CVE-2020-11996 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8... Important tomcat 完成修复 2025-06-16 2026-01-04
CVE-2020-10177 Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. Moderate python-pillow 完成修复 2025-06-16 2026-03-19
CVE-2014-4322 drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android con... Moderate kernel 完成修复 2025-06-16 2026-01-23
CVE-2025-22874 No description is available for this CVE. Important golang, go-toolset:an8 完成修复 2025-06-13 2025-12-17
CVE-2019-10247 In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and J... Moderate jetty, eclipse:an8 完成修复 2025-06-13 2026-07-09
CVE-2019-10241 In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions i... Moderate jetty 完成修复 2025-06-13 2026-07-09
CVE-2025-6021 No description is available for this CVE. Moderate libxml2 完成修复 2025-06-12 2026-07-11
CVE-2025-5991 A use-after-free vulnerability has been discovered in Qt's QHttp2ProtocolHandler function. This vulnerability only affects HTTP... Moderate qt5 完成修复 2025-06-12 2026-03-19
CVE-2025-5601 Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafte... Moderate wireshark 完成修复 2025-06-12 2026-01-22
CVE-2025-49796 No description is available for this CVE. Important libxml2 完成修复 2025-06-12 2026-01-04
CVE-2025-49795 A null pointer dereference vulnerability was discovered in the libxml2. The issue occurs in the xmlSchematronFormatReport funct... Important libxml2 完成修复 2025-06-12 2026-01-04
CVE-2025-49794 No description is available for this CVE. Important libxml2 完成修复 2025-06-12 2026-01-04
CVE-2025-49710 An integer overflow was present in OrderedHashTable used by the JavaScript engine This vulnerability affects Firefox < 139.0.... Important firefox 完成修复 2025-06-11 2025-12-29
CVE-2025-49709 Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4. Important firefox 完成修复 2025-06-11 2025-12-29
CVE-2025-30348 encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a st... Moderate qt 完成修复 2025-06-11 2026-07-10
CVE-2024-48426 A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing ... Moderate qt5-qt3d 完成修复 2025-06-11 2026-03-19
CVE-2024-47081 Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third ... Moderate python-requests, python3.11-pip, python-pip, python39:3.9, fence-agents, python27:2.7, resource-agents 完成修复 2025-06-11 2026-06-24
CVE-2025-5683 When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from v... Moderate qt5 完成修复 2025-06-10 2026-03-19
CVE-2025-5399 Due to a mistake in libcurl's WebSocket code, a malicious server can send a\nparticularly crafted packet which makes libcurl ge... Moderate curl 完成修复 2025-06-10 2026-03-19
CVE-2019-5747 An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, serv... Low busybox 完成修复 2025-06-10 2026-03-19
CVE-2018-20679 An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, clien... Low busybox 完成修复 2025-06-10 2026-01-22
CVE-2025-29787 zip is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of af... Important zip 完成修复 2025-06-09 2026-01-04
CVE-2025-22870 Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO... Moderate grafana, weldr-client, containernetworking-plugins, osbuild-composer, git-lfs, rhc, golang, grafana-pcp 完成修复 2025-06-09 2025-12-11
CVE-2024-8235 A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case ... Moderate libvirt 完成修复 2025-06-09 2025-12-18
CVE-2024-51988 RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API... Moderate rabbitmq-server 完成修复 2025-06-09 2026-07-10
CVE-2024-45306 Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a ... Moderate vim 完成修复 2025-06-09 2026-01-22
CVE-2024-45231 An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used... Moderate python-django 完成修复 2025-06-09 2026-03-19
CVE-2024-39695 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An o... Moderate exiv2 完成修复 2025-06-09 2026-07-11
CVE-2024-32228 FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. Moderate ffmpeg 完成修复 2025-06-09 2025-12-06
CVE-2024-25112 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A de... Moderate exiv2 完成修复 2025-06-09 2026-07-11
CVE-2024-24826 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An o... Moderate exiv2 完成修复 2025-06-09 2026-01-22
CVE-2024-24787 On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due... Moderate golang 完成修复 2025-06-09 2025-12-11
CVE-2024-22420 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architect... Moderate jupyterlab 完成修复 2025-06-09 2026-01-22
CVE-2024-21733 Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: f... Moderate tomcat 完成修复 2025-06-09 2026-06-26
CVE-2023-40403 A flaw was found in libxslt package. Processing web content may disclose sensitive information. This issue was addressed with i... Moderate libxslt 完成修复 2025-06-09 2026-03-19
CVE-2022-49800 In the Linux kernel, the following vulnerability has been resolved:\ntracing: Fix memory leak in testgen_synth_cmd() and test... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 完成修复 2025-06-07 2026-01-30
CVE-2025-5745 The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector reg... Important glibc 完成修复 2025-06-06 2025-12-11
CVE-2025-5702 The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector regi... Important glibc 完成修复 2025-06-06 2025-12-11
CVE-2023-5680 If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database... Moderate bind9.16, bind 完成修复 2025-06-06 2026-07-11
CVE-2023-5568 A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vuln... Moderate samba 完成修复 2025-06-06 2026-07-09
CVE-2023-48733 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypas... Moderate edk2 完成修复 2025-06-06 2026-03-19
CVE-2023-47641 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vu... Moderate python-aiohttp 完成修复 2025-06-06 2026-06-24
CVE-2023-43490 Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privil... Moderate microcode_ctl 完成修复 2025-06-06 2026-07-10
CVE-2023-40030 Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo... Moderate rust 完成修复 2025-06-06 2025-12-16
CVE-2023-39368 Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentiall... Moderate microcode_ctl 完成修复 2025-06-06 2026-07-10
CVE-2023-38575 Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user t... Moderate microcode_ctl 完成修复 2025-06-06 2026-07-10
CVE-2023-22313 Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potent... Low qatlib 完成修复 2025-06-06 2026-07-10
CVE-2011-10007 File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when grep() encounters a crafted filename. A... Important perl-File-Find-Rule-Perl, perl-File-Find-Rule 完成修复 2025-06-06 2025-12-29
CVE-2025-4435 When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be... Important python3.11, python3, python39:3.9, python, python36:3.6 完成修复 2025-06-05 2025-12-29
CVE-2025-4330 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modifi... Important python3.11, python3, python39:3.9, python, python36:3.6 完成修复 2025-06-05 2026-01-08
CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modifi... Important python3.11, python3, python39:3.9, python, python36:3.6 完成修复 2025-06-05 2026-01-08
CVE-2025-27796 ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to ... Moderate GraphicsMagick 完成修复 2025-06-05 2026-07-11
CVE-2025-27795 ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. Moderate GraphicsMagick 完成修复 2025-06-05 2026-07-11
CVE-2023-49082 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an at... Moderate python-aiohttp 完成修复 2025-06-05 2026-06-25
CVE-2023-46445 An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle at... Moderate python-asyncssh 完成修复 2025-06-05 2026-06-25
CVE-2023-46407 FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_v... Moderate ffmpeg 完成修复 2025-06-05 2025-12-06
CVE-2023-39978 ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw. Low ImageMagick 完成修复 2025-06-05 2026-01-22
CVE-2023-3745 A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may all... Moderate ImageMagick 完成修复 2025-06-05 2026-03-19
CVE-2023-0809 In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets. Moderate mosquitto 完成修复 2025-06-05 2026-01-22
CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. \n \n \n \nA special BeanIntrospector class was added in version 1.9.2... Important javapackages-tools:201801, apache-commons-beanutils 完成修复 2025-06-04 2026-01-06
CVE-2024-6614 The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vuln... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2024-6610 Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent ... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2024-6600 Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating ... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2023-37210 A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2023-37206 Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicio... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2023-37205 The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2023-37204 A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive comput... Moderate firefox 完成修复 2025-06-04 2026-01-20
CVE-2022-47952 lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even wi... Low lxc 完成修复 2025-06-04 2026-03-19
CVE-2022-3647 DISPUTED A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the func... Low redis, redis:6, redis:5 完成修复 2025-06-04 2026-03-19
CVE-2022-29869 cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but... Moderate cifs-utils 完成修复 2025-06-04 2026-03-19
CVE-2021-45832 A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (... Moderate hdf5 完成修复 2025-06-04 2026-03-19
CVE-2021-40266 FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference. Moderate freeimage 完成修复 2025-06-04 2026-07-11
CVE-2021-40264 NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp. Moderate freeimage 完成修复 2025-06-04 2026-07-11
CVE-2021-40262 A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp. Moderate freeimage 完成修复 2025-06-04 2026-07-11
CVE-2021-3997 A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when to... Moderate systemd 完成修复 2025-06-04 2026-03-19
CVE-2021-28429 Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attacke... Moderate ffmpeg 完成修复 2025-06-04 2025-12-06
CVE-2021-0127 Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial... Moderate microcode_ctl 完成修复 2025-06-04 2026-07-10
CVE-2020-26683 A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive inf... Moderate mupdf 完成修复 2025-06-04 2026-03-19
CVE-2020-21490 An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory o... Moderate binutils 完成修复 2025-06-04 2025-12-11

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""