| CVE-2023-46048 |
Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be ... |
Moderate |
texlive, texlive-base |
是 |
完成修复 |
2025-04-11 |
2026-06-24 |
| CVE-2023-45919 |
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no... |
Moderate |
mesa |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2023-43114 |
An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using th... |
Moderate |
qt5 |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2023-39328 |
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and... |
Moderate |
openjpeg2 |
是 |
完成修复 |
2025-04-11 |
2026-07-10 |
| CVE-2023-39327 |
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously pri... |
Moderate |
openjpeg2 |
是 |
完成修复 |
2025-04-11 |
2026-07-10 |
| CVE-2021-46312 |
An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by ... |
Moderate |
djvulibre |
是 |
完成修复 |
2025-04-11 |
2026-07-13 |
| CVE-2021-46310 |
An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero. |
Moderate |
djvulibre |
是 |
完成修复 |
2025-04-11 |
2026-07-13 |
| CVE-2020-29509 |
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during ... |
Moderate |
golang, go-toolset:an8 |
是 |
完成修复 |
2025-04-11 |
2025-12-11 |
| CVE-2020-12404 |
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functi... |
Moderate |
firefox |
否 |
完成修复 |
2025-04-11 |
2026-01-20 |
| CVE-2019-17003 |
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. |
Moderate |
firefox |
否 |
完成修复 |
2025-04-11 |
2026-01-20 |
| CVE-2019-11252 |
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount... |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2019-11251 |
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination ... |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2019-11249 |
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes... |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2019-11247 |
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the res... |
Important |
kubernetes |
否 |
完成修复 |
2025-04-11 |
2026-01-06 |
| CVE-2019-11246 |
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes... |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-11 |
2026-03-18 |
| CVE-2025-24375 |
Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-4568 |
In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. |
Low |
xpdf |
是 |
完成修复 |
2025-04-10 |
2026-07-09 |
| CVE-2024-3900 |
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText. |
Low |
xpdf |
是 |
完成修复 |
2025-04-10 |
2026-07-09 |
| CVE-2024-35200 |
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker p... |
Moderate |
nginx |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-34161 |
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Tra... |
Moderate |
nginx |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-32760 |
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NG... |
Moderate |
nginx |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-32111 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Rel... |
Moderate |
wordpress |
是 |
完成修复 |
2025-04-10 |
2026-03-27 |
| CVE-2024-31584 |
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. |
Moderate |
pytorch |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-31111 |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPre... |
Moderate |
wordpress |
是 |
完成修复 |
2025-04-10 |
2026-03-27 |
| CVE-2024-31079 |
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker p... |
Moderate |
nginx |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-25710 |
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commo... |
Moderate |
apache-commons-compress |
是 |
完成修复 |
2025-04-10 |
2026-07-11 |
| CVE-2024-2397 |
Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DL... |
Moderate |
libpcap, tcpdump |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-2236 |
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiat... |
Moderate |
libgcrypt |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2024-21503 |
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_l... |
Moderate |
python-black |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21185 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21179 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21177 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21176 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are aff... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-26 |
| CVE-2024-21173 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21171 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21165 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are aff... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21163 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21162 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2024-21142 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that a... |
Moderate |
mysql, mysql:8.0 |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2023-42366 |
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. |
Moderate |
busybox |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2023-42365 |
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. |
Moderate |
busybox |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2023-42364 |
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in t... |
Moderate |
busybox |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2023-42363 |
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
Moderate |
busybox |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2023-40170 |
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on /files/ URLs could allow... |
Moderate |
python-jupyter-server |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2023-39968 |
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to kno... |
Moderate |
python-jupyter-server |
是 |
完成修复 |
2025-04-10 |
2026-06-24 |
| CVE-2023-39929 |
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to... |
Moderate |
libva |
是 |
完成修复 |
2025-04-10 |
2026-07-11 |
| CVE-2023-33201 |
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications ... |
Moderate |
bouncycastle |
是 |
完成修复 |
2025-04-10 |
2026-07-11 |
| CVE-2023-22051 |
Vulnerability in the Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: GraalVM Co... |
Low |
java-17-openjdk |
否 |
完成修复 |
2025-04-10 |
2025-12-05 |
| CVE-2022-4964 |
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. |
Moderate |
pipewire |
是 |
完成修复 |
2025-04-10 |
2026-07-10 |
| CVE-2022-4886 |
Ingress-nginx path sanitization can be bypassed with log_format directive. |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2022-48682 |
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink. |
Moderate |
fdupes |
否 |
完成修复 |
2025-04-10 |
2026-01-22 |
| CVE-2022-48545 |
An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02. |
Moderate |
xpdf |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2021-25736 |
Kube-proxy\n on Windows can unintentionally forward traffic to local processes \nlistening on the same port (“spec.ports[*].p... |
Moderate |
kubernetes |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2020-24294 |
Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attac... |
Moderate |
freeimage |
是 |
完成修复 |
2025-04-10 |
2026-07-11 |
| CVE-2020-22524 |
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial ... |
Moderate |
freeimage |
是 |
完成修复 |
2025-04-10 |
2026-07-11 |
| CVE-2020-21679 |
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denia... |
Moderate |
ImageMagick |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2018-25100 |
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the ... |
Moderate |
perl-Mojolicious |
是 |
完成修复 |
2025-04-10 |
2026-03-18 |
| CVE-2025-32414 |
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) be... |
Moderate |
libxml2 |
是 |
完成修复 |
2025-04-09 |
2026-07-11 |
| CVE-2025-30427 |
A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17... |
Moderate |
webkitgtk4, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2025-04-09 |
2026-07-11 |
| CVE-2025-24216 |
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 ... |
Moderate |
webkitgtk4, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2025-04-09 |
2026-07-11 |
| CVE-2025-24213 |
This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2025-04-09 |
2025-12-29 |
| CVE-2025-24209 |
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2025-04-09 |
2026-01-04 |
| CVE-2025-24208 |
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. L... |
Moderate |
webkitgtk4, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2025-04-09 |
2026-07-11 |
| CVE-2024-54551 |
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonom... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2025-04-09 |
2026-01-04 |
| CVE-2023-29453 |
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks... |
Critical |
golang |
是 |
完成修复 |
2025-04-07 |
2025-12-10 |
| CVE-2025-32365 |
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2S... |
Moderate |
poppler |
否 |
完成修复 |
2025-04-06 |
2026-01-25 |
| CVE-2025-32364 |
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handl... |
Moderate |
poppler |
否 |
完成修复 |
2025-04-06 |
2026-01-25 |
| CVE-2025-27220 |
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeEle... |
Moderate |
ruby, ruby:3.3 |
是 |
完成修复 |
2025-04-06 |
2026-03-18 |
| CVE-2025-27219 |
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (D... |
Moderate |
ruby, ruby:3.3 |
是 |
完成修复 |
2025-04-06 |
2026-06-24 |
| CVE-2025-32053 |
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a hea... |
Moderate |
mingw-freetype, spice-client-win, libsoup |
是 |
完成修复 |
2025-04-04 |
2026-07-10 |
| CVE-2025-32052 |
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. |
Moderate |
mingw-freetype, spice-client-win, libsoup |
是 |
完成修复 |
2025-04-04 |
2026-07-10 |
| CVE-2025-32051 |
A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This... |
Moderate |
libsoup |
是 |
完成修复 |
2025-04-04 |
2026-03-18 |
| CVE-2025-32050 |
A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under... |
Moderate |
mingw-freetype, spice-client-win, libsoup |
是 |
完成修复 |
2025-04-04 |
2026-07-10 |
| CVE-2025-32049 |
A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to alloc... |
Important |
libsoup |
否 |
完成修复 |
2025-04-04 |
2026-01-05 |
| CVE-2025-3155 |
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerabi... |
Moderate |
yelp |
否 |
完成修复 |
2025-04-04 |
2026-01-22 |
| CVE-2025-2784 |
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_wh... |
Important |
libsoup3, libsoup |
否 |
完成修复 |
2025-04-04 |
2026-01-04 |
| CVE-2025-23108 |
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the ... |
Moderate |
firefox |
否 |
完成修复 |
2025-04-04 |
2026-01-20 |
| CVE-2025-0246 |
When using an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Android opera... |
Moderate |
firefox |
否 |
完成修复 |
2025-04-04 |
2026-01-20 |
| CVE-2025-0245 |
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypas... |
Low |
firefox |
否 |
完成修复 |
2025-04-04 |
2026-01-20 |
| CVE-2025-0244 |
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Andr... |
Moderate |
firefox |
否 |
完成修复 |
2025-04-04 |
2026-01-20 |
| CVE-2024-4773 |
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could ... |
Important |
firefox |
否 |
完成修复 |
2025-04-04 |
2025-12-29 |
| CVE-2024-4766 |
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential ... |
Moderate |
firefox |
否 |
完成修复 |
2025-04-04 |
2026-01-20 |
| CVE-2024-4765 |
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another app... |
Important |
firefox |
否 |
完成修复 |
2025-04-04 |
2025-12-29 |
| CVE-2025-21986 |
In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking notification chain to a... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2025-21970 |
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state chec... |
Moderate |
kernel:5.10, kernel:4.18, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2025-21961 |
In the Linux kernel, the following vulnerability has been resolved: \n \neth: bnxt: fix truesize for mb-xdp-pass case \n \nWhen... |
Important |
kernel:5.10, kernel:4.18, kernel:4.19, kernel:6.6 |
是 |
完成修复 |
2025-04-03 |
2025-12-23 |
| CVE-2025-21960 |
In the Linux kernel, the following vulnerability has been resolved: \n \neth: bnxt: do not update checksum in bnxt_xdp_build_sk... |
Important |
kernel:5.10, kernel:4.18, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-04-03 |
2025-12-31 |
| CVE-2025-21953 |
In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove()\n... |
Moderate |
kernel:5.10, kernel:4.18, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2025-21929 |
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in hid_isht... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2025-21927 |
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_re... |
Moderate |
kernel:4.19, kernel:6.6, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2025-21926 |
In the Linux kernel, the following vulnerability has been resolved: \n \nnet: gso: fix ownership in _udp_gso_segment \n \nIn ... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-04-03 |
2025-12-31 |
| CVE-2025-21915 |
In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show()\n... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10, kernel:4.18 |
否 |
完成修复 |
2025-04-03 |
2026-01-17 |
| CVE-2024-7866 |
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow. |
Moderate |
xpdf |
是 |
完成修复 |
2025-04-03 |
2026-07-10 |
| CVE-2024-7347 |
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NG... |
Moderate |
nginx:1.22, nginx |
是 |
完成修复 |
2025-04-03 |
2026-03-18 |
| CVE-2024-7246 |
It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend s... |
Moderate |
grpc |
是 |
完成修复 |
2025-04-03 |
2026-03-18 |
| CVE-2024-47554 |
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class ... |
Moderate |
apache-commons-io |
是 |
完成修复 |
2025-04-03 |
2026-07-11 |
| CVE-2024-45993 |
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb. |
Moderate |
giflib |
是 |
完成修复 |
2025-04-03 |
2026-07-13 |
| CVE-2024-45620 |
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which wo... |
Low |
opensc |
是 |
完成修复 |
2025-04-03 |
2026-07-10 |
| CVE-2024-45619 |
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Dev... |
Moderate |
opensc |
是 |
完成修复 |
2025-04-03 |
2026-07-09 |
| CVE-2024-45618 |
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would prese... |
Low |
opensc |
是 |
完成修复 |
2025-04-03 |
2026-07-10 |