CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2020-8563 In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials wil... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-8561 A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or Valida... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-8559 The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an ... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-8557 The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a po... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-8555 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-8551 The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial o... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-36604 hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. Moderate pcs 完成修复 2025-04-22 2026-07-09
CVE-2020-35538 A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. Low libjpeg-turbo 完成修复 2025-04-22 2026-03-27
CVE-2020-26979 When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture t... Moderate firefox 完成修复 2025-04-22 2026-01-20
CVE-2020-26977 By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the... Moderate firefox 完成修复 2025-04-22 2026-01-20
CVE-2020-26975 When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could... Moderate firefox 完成修复 2025-04-22 2026-01-20
CVE-2020-26963 Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introduci... Moderate firefox 完成修复 2025-04-22 2026-01-20
CVE-2020-26954 When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths a... Moderate firefox 完成修复 2025-04-22 2026-01-20
CVE-2020-23904 A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.... Moderate speex 完成修复 2025-04-22 2026-03-18
CVE-2020-2309 A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read perm... Moderate kubernetes 完成修复 2025-04-22 2026-03-18
CVE-2020-16587 A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ... Moderate OpenEXR 完成修复 2025-04-22 2026-03-18
CVE-2025-30219 RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modif... Moderate rabbitmq-server 完成修复 2025-04-21 2026-07-10
CVE-2025-30211 Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a... Important erlang 完成修复 2025-04-21 2026-01-07
CVE-2024-9427 A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could b... Moderate koji 完成修复 2025-04-21 2026-01-25
CVE-2024-53920 In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untr... Important emacs 完成修复 2025-04-21 2025-12-29
CVE-2024-52333 An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially ... Important dcmtk 完成修复 2025-04-21 2025-12-29
CVE-2024-40794 This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6,... Moderate webkitgtk4, webkitgtk3, webkitgtk, webkit2gtk3 完成修复 2025-04-21 2026-07-11
CVE-2024-1682 An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket ... Moderate python-requests 完成修复 2025-04-21 2026-03-18
CVE-2024-10977 Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbit... Low postgresql 完成修复 2025-04-21 2026-01-25
CVE-2020-5419 RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for a... Moderate rabbitmq-server 完成修复 2025-04-21 2026-07-10
CVE-2020-16589 A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp tha... Moderate OpenEXR 完成修复 2025-04-21 2026-03-18
CVE-2019-9923 pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have mal... Important tar 完成修复 2025-04-21 2026-01-08
CVE-2019-6128 The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. Important libtiff 完成修复 2025-04-21 2026-01-05
CVE-2019-11287 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions p... Moderate rabbitmq-server 完成修复 2025-04-21 2026-07-10
CVE-2025-30698 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Moderate java-1.6.0-openjdk, java-17-openjdk, java-1.7.0-openjdk, java-11-openjdk, java-1.8.0-openjdk, java-21-openjdk 完成修复 2025-04-18 2025-12-05
CVE-2025-30691 Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Or... Moderate java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk 完成修复 2025-04-18 2025-12-05
CVE-2020-13790 libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input... Important libjpeg-turbo 完成修复 2025-04-17 2026-01-06
CVE-2025-21583 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql, mysql:8.0 完成修复 2025-04-16 2026-03-18
CVE-2024-7254 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP ta... Important protobuf 完成修复 2025-04-16 2025-12-29
CVE-2023-5616 In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd ... Moderate gnome-control-center 完成修复 2025-04-16 2026-07-13
CVE-2020-17527 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.... Important tomcat 完成修复 2025-04-16 2026-01-04
CVE-2023-42970 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma... Important webkitgtk4, webkitgtk3, webkit2gtk3 完成修复 2025-04-15 2025-12-29
CVE-2023-42875 Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watc... Important webkitgtk4, webkitgtk3, webkit2gtk3 完成修复 2025-04-15 2025-12-29
CVE-2021-30134 php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and ... Moderate curl 完成修复 2025-04-15 2026-01-25
CVE-2025-32914 A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This ... Important libsoup3, libsoup 完成修复 2025-04-14 2026-01-04
CVE-2025-32913 A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer ... Important libsoup3, libsoup 完成修复 2025-04-14 2025-12-29
CVE-2025-32912 A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the li... Moderate libsoup 完成修复 2025-04-14 2026-07-11
CVE-2025-32910 A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may ... Moderate mingw-freetype, spice-client-win, libsoup 完成修复 2025-04-14 2026-07-10
CVE-2025-32909 A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The ... Moderate mingw-freetype, spice-client-win, libsoup 完成修复 2025-04-14 2026-07-10
CVE-2025-32908 A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authori... Important libsoup3, libsoup 完成修复 2025-04-14 2025-12-30
CVE-2025-32907 A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This fla... Important libsoup3, mingw-freetype, spice-client-win, libsoup 完成修复 2025-04-14 2025-12-29
CVE-2025-32906 A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This fl... Important libsoup3, mingw-freetype, spice-client-win, libsoup 完成修复 2025-04-14 2025-12-29
CVE-2025-31344 Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2... Important java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, giflib 完成修复 2025-04-14 2025-12-05
CVE-2025-24813 Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious co... Moderate tomcat 完成修复 2025-04-14 2026-06-26
CVE-2021-43809 Bundler is a package for managing application dependencies in Ruby. In bundler versions before 2.2.33, when working with un... Important ruby, ruby:2.5, rubygem-bundler, ruby:3.0 完成修复 2025-04-13 2026-01-04
CVE-2020-14039 In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requireme... Moderate golang, go-toolset:an8 完成修复 2025-04-13 2025-12-11
CVE-2025-29088 An issue in sqlite v.3.49.0 allows an attacker to cause a denial of service via the SQLITE_DBCONFIG_LOOKASIDE component Important sqlite, mingw-sqlite 完成修复 2025-04-12 2026-01-04
CVE-2020-36561 Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outsi... Critical unzip 完成修复 2025-04-12 2026-01-07
CVE-2025-3359 A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. Moderate gnuplot 完成修复 2025-04-11 2026-07-11
CVE-2025-3198 A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the f... Low binutils 完成修复 2025-04-11 2025-12-11
CVE-2025-3035 By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would l... Moderate firefox 完成修复 2025-04-11 2026-01-20
CVE-2024-51479 Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is perform... Important firefox, thunderbird 完成修复 2025-04-11 2025-12-29
CVE-2024-38460 In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially expose... Moderate sonarqube 完成修复 2025-04-11 2026-07-09
CVE-2024-3248 In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. Low xpdf 完成修复 2025-04-11 2026-07-09
CVE-2024-3247 In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow. Low xpdf 完成修复 2025-04-11 2026-07-09
CVE-2024-3177 A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets po... Low kubernetes 完成修复 2025-04-11 2026-03-18
CVE-2024-31585 FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This... Moderate ffmpeg 完成修复 2025-04-11 2025-12-06
CVE-2024-2971 Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF ... Low xpdf 完成修复 2025-04-11 2026-07-09
CVE-2024-29508 Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the funct... Low ghostscript 完成修复 2025-04-11 2026-01-25
CVE-2024-28577 Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of s... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28575 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28574 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28573 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28570 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28568 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28567 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (D... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-28562 Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via t... Moderate freeimage 完成修复 2025-04-11 2026-07-11
CVE-2024-21134 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that ar... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-21130 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-21129 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-21127 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-21125 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-20996 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37... Moderate mysql, mysql:8.0 完成修复 2025-04-11 2026-06-24
CVE-2024-1580 An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory cor... Moderate dav1d 完成修复 2025-04-11 2026-07-13
CVE-2024-1454 The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process u... Low opensc 完成修复 2025-04-11 2026-07-10
CVE-2024-0232 A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allow... Moderate sqlite 完成修复 2025-04-11 2026-07-09
CVE-2023-5692 WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirectguess... Moderate wordpress 完成修复 2025-04-11 2026-03-18
CVE-2023-5341 A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. Moderate ImageMagick 完成修复 2025-04-11 2026-07-09
CVE-2023-51797 Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfi... Moderate ffmpeg 完成修复 2025-04-11 2025-12-06
CVE-2023-51594 BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attacker... Low bluez 完成修复 2025-04-11 2026-06-24
CVE-2023-51592 BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows... Moderate bluez 完成修复 2025-04-11 2026-07-11
CVE-2023-51589 BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allow... Moderate bluez 完成修复 2025-04-11 2026-07-11
CVE-2023-51580 BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabilit... Moderate bluez 完成修复 2025-04-11 2026-07-11
CVE-2023-50979 Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding. Moderate cryptopp 完成修复 2025-04-11 2026-03-18
CVE-2023-50007 Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via theav_sample... Moderate ffmpeg 完成修复 2025-04-11 2025-12-06
CVE-2023-49558 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in th... Moderate yasm 完成修复 2025-04-11 2026-07-10
CVE-2023-49557 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function i... Moderate yasm 完成修复 2025-04-11 2026-07-10
CVE-2023-49556 Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the exprdelete... Moderate yasm 完成修复 2025-04-11 2026-07-10
CVE-2023-49555 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the mod... Moderate yasm 完成修复 2025-04-11 2026-07-10
CVE-2023-49554 Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive ... Moderate yasm 完成修复 2025-04-11 2026-07-10
CVE-2023-49284 fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unic... Moderate fish 完成修复 2025-04-11 2026-07-11
CVE-2023-49100 Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in reg... Moderate arm-trusted-firmware 完成修复 2025-04-11 2026-07-11
CVE-2023-49080 The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Ju... Moderate python-jupyter-server 完成修复 2025-04-11 2026-06-24
CVE-2023-46361 Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. Moderate jbig2dec 完成修复 2025-04-11 2026-06-24
CVE-2023-46118 RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vul... Moderate rabbitmq-server 完成修复 2025-04-11 2026-07-10

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""