| CVE-2017-15299 |
The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstanti... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-15126 |
A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of ... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-15116 |
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL po... |
Low |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-14340 |
The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-14156 |
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a cert... |
Low |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-14140 |
The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target proc... |
Low |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2017-14106 |
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-13715 |
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_pr... |
Important |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2017-13694 |
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush th... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-13693 |
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the o... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-13221 |
An elevation of privilege vulnerability in the Upstream kernel wifi driver. Product: Android. Versions: Android kernel. Android... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10, kernel |
否 |
完成修复 |
2025-05-22 |
2025-12-09 |
| CVE-2017-13080 |
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, all... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-25 |
| CVE-2017-12192 |
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 doe... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-12190 |
The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting wh... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-1000407 |
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2017-1000405 |
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the TH... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2017-1000380 |
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting i... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2017-1000379 |
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the sta... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2017-1000364 |
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently la... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2017-1000253 |
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb37... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-09 |
| CVE-2017-1000252 |
The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-18 |
| CVE-2017-1000251 |
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.1... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2017-1000112 |
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_ap... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2017-0861 |
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain pr... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2016-9755 |
The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial o... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-9754 |
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 misha... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-9685 |
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a de... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2016-9313 |
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with succes... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-9178 |
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain in... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2016-8666 |
The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) ... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-8655 |
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a de... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-8630 |
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local user... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-18 |
| CVE-2016-7910 |
Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local user... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-7425 |
The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a ... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2016-6516 |
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to caus... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-6213 |
fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows lo... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-22 |
| CVE-2016-6198 |
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed t... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-6197 |
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-6187 |
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-6162 |
net/core/skbuff.c in the Linux kernel 4.7-rc6 allows local users to cause a denial of service (panic) or possibly have unspecif... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2016-5344 |
Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android co... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2016-5342 |
Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2016-4998 |
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users t... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-4565 |
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local ... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-3157 |
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2025-05-22 |
2026-01-25 |
| CVE-2016-20022 |
In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of a... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-10907 |
An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the fu... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-10906 |
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-10318 |
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encr... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-10229 |
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe ... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-10208 |
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups,... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2016-10200 |
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges o... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2016-10044 |
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it e... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2015-8966 |
arch/arm/kernel/sysoabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-22 |
| CVE-2015-8964 |
The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensi... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-22 |
| CVE-2015-8539 |
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via ... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2025-12-08 |
| CVE-2015-7312 |
Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux ke... |
Low |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
是 |
完成修复 |
2025-05-22 |
2026-01-23 |
| CVE-2015-4001 |
Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linu... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2012-6703 |
Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux ... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-05-22 |
2026-01-17 |
| CVE-2025-4948 |
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME... |
Important |
libsoup3, libsoup |
否 |
完成修复 |
2025-05-21 |
2025-12-30 |
| CVE-2025-47273 |
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal... |
Moderate |
python3.11-setuptools, python-setuptools, python39:3.9, fence-agents, python3-setuptools |
是 |
完成修复 |
2025-05-21 |
2026-07-13 |
| CVE-2025-37923 |
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix oob write in trace_seq_to_buffer() syzbo... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-21 |
2026-01-17 |
| CVE-2025-31257 |
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handlin... |
Important |
webkitgtk,webkit2gtk3 |
否 |
完成修复 |
2025-05-21 |
2026-01-04 |
| CVE-2025-31205 |
A flaw was found in WebKitGTK. A malicious website may steal data cross-origin due to improper security checks within the web b... |
Moderate |
webkitgtk4, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2025-05-21 |
2026-07-11 |
| CVE-2025-31164 |
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_l... |
Moderate |
transfig |
是 |
完成修复 |
2025-05-21 |
2026-06-26 |
| CVE-2025-31163 |
Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_pattern... |
Moderate |
transfig |
是 |
完成修复 |
2025-05-21 |
2026-06-26 |
| CVE-2025-31162 |
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_s... |
Moderate |
transfig |
是 |
完成修复 |
2025-05-21 |
2026-06-26 |
| CVE-2025-2509 |
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access wit... |
Moderate |
virglrenderer |
是 |
完成修复 |
2025-05-21 |
2026-03-19 |
| CVE-2025-23165 |
In Node.js, the ReadFileUtf8 internal binding leaks memory due to a corrupted pointer in uv_fs_s.file: a UTF-16 path buffer... |
Low |
nodejs, nodejs:20 |
是 |
完成修复 |
2025-05-21 |
2026-03-19 |
| CVE-2025-21756 |
A flaw was found in the Linux kernel's VMware network driver, where an improperly timed socket unbinding could result in a use-... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-21 |
2026-01-17 |
| CVE-2023-53146 |
In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer... |
Moderate |
kernel:4.19, kernel:6.6, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-21 |
2026-01-17 |
| CVE-2015-0410 |
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; J... |
Moderate |
java-1.8.0-openjdk |
否 |
完成修复 |
2025-05-21 |
2025-12-05 |
| CVE-2015-0406 |
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availabi... |
Moderate |
java-1.8.0-openjdk |
否 |
完成修复 |
2025-05-21 |
2025-12-05 |
| CVE-2014-7192 |
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational A... |
Important |
nodejs, nodejs:20 |
否 |
完成修复 |
2025-05-21 |
2026-01-06 |
| CVE-2025-4919 |
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vuln... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2025-05-20 |
2025-12-29 |
| CVE-2025-46398 |
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read... |
Low |
transfig |
是 |
完成修复 |
2025-05-20 |
2026-06-24 |
| CVE-2025-37891 |
In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow at UMP SysEx message conv... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-05-20 |
2026-01-17 |
| CVE-2002-2438 |
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly... |
Important |
kernel:4.18, kernel:3.10, kernel:6.6, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2025-05-20 |
2025-12-08 |
| CVE-2025-4918 |
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object. This vulnerability affects Fir... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2025-05-19 |
2026-01-20 |
| CVE-2025-47287 |
Tornado is a Python web framework and asynchronous networking library. When Tornado's multipart/form-data parser encounters... |
Important |
pcs, python-tornado |
否 |
完成修复 |
2025-05-19 |
2025-12-29 |
| CVE-2025-46399 |
In xfig diagramming tool, a segmentation fault in fig2dev allows memory corruption via local input manipulation at genge_itp_sp... |
Low |
transfig |
是 |
完成修复 |
2025-05-19 |
2026-06-24 |
| CVE-2025-46397 |
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation at the b... |
Low |
transfig |
是 |
完成修复 |
2025-05-19 |
2026-06-24 |
| CVE-2025-4478 |
A flaw was found in the gnome-remote-desktop used by Anaconda's remote install feature, where a crafted RDP packet could trigge... |
Moderate |
gnome-remote-desktop, freerdp |
是 |
完成修复 |
2025-05-19 |
2026-03-19 |
| CVE-2025-4802 |
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controll... |
Moderate |
glibc, compat-glibc |
否 |
完成修复 |
2025-05-17 |
2025-12-11 |
| CVE-2025-47278 |
Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration wa... |
Low |
python-flask |
是 |
完成修复 |
2025-05-16 |
2026-03-27 |
| CVE-2025-20623 |
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for s... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-05-16 |
2026-07-10 |
| CVE-2025-20103 |
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to pot... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-05-16 |
2026-07-10 |
| CVE-2025-20054 |
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-05-16 |
2026-07-10 |
| CVE-2024-53907 |
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and strip... |
Moderate |
python-django |
是 |
完成修复 |
2025-05-16 |
2026-06-24 |
| CVE-2024-48869 |
Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using ... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-05-16 |
2026-07-10 |
| CVE-2024-45332 |
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in th... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-05-16 |
2026-07-10 |
| CVE-2024-0397 |
A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods ... |
Low |
python3.11, python3, python |
是 |
完成修复 |
2025-05-16 |
2026-06-24 |
| CVE-2025-4207 |
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of serv... |
Moderate |
postgresql:12, libpq, postgresql:13, postgresql:9.6, postgresql:10, postgresql, postgresql:15 |
是 |
完成修复 |
2025-05-14 |
2026-07-10 |
| CVE-2025-22871 |
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit reques... |
Moderate |
grafana, weldr-client, go-toolset:an8, container-tools:2.0, skopeo, container-tools:3.0, container-tools:an8, osbuild-composer, git-lfs, golang, container-tools:1.0, grafana-pcp |
是 |
完成修复 |
2025-05-14 |
2025-12-11 |
| CVE-2025-1974 |
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the po... |
Critical |
kubernetes |
否 |
完成修复 |
2025-05-14 |
2026-01-10 |
| CVE-2024-58250 |
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. |
Important |
ppp |
否 |
完成修复 |
2025-05-14 |
2026-01-04 |
| CVE-2024-48949 |
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.edds... |
Important |
pcs, grafana, mozjs60, thunderbird, polkit, gjs |
否 |
完成修复 |
2025-05-14 |
2026-01-09 |
| CVE-2024-48910 |
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototyp... |
Important |
grafana |
否 |
完成修复 |
2025-05-14 |
2026-01-04 |
| CVE-2024-47835 |
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been ... |
Moderate |
gstreamer1-plugins-base |
是 |
完成修复 |
2025-05-14 |
2026-07-11 |
| CVE-2024-47601 |
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been ... |
Moderate |
gstreamer1-plugins-good |
是 |
完成修复 |
2025-05-14 |
2026-07-11 |