| CVE-2021-31239 |
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c functi... |
Important |
sqlite |
否 |
完成修复 |
2025-03-20 |
2026-01-09 |
| CVE-2021-20299 |
A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trig... |
Low |
OpenEXR |
是 |
完成修复 |
2025-03-20 |
2026-03-18 |
| CVE-2020-36773 |
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) bec... |
Important |
ghostscript |
否 |
完成修复 |
2025-03-20 |
2026-01-06 |
| CVE-2020-36138 |
An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial o... |
Important |
ffmpeg |
否 |
完成修复 |
2025-03-20 |
2025-12-06 |
| CVE-2020-35498 |
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious ... |
Moderate |
openvswitch |
是 |
完成修复 |
2025-03-20 |
2026-03-18 |
| CVE-2020-24742 |
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, a... |
Moderate |
qt, qt5 |
是 |
完成修复 |
2025-03-20 |
2026-03-18 |
| CVE-2020-24165 |
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges... |
Important |
qemu, qemu-kvm |
否 |
完成修复 |
2025-03-20 |
2025-12-10 |
| CVE-2020-21427 |
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run... |
Important |
freeimage |
否 |
完成修复 |
2025-03-20 |
2026-01-07 |
| CVE-2020-21426 |
Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run a... |
Important |
freeimage |
否 |
完成修复 |
2025-03-20 |
2026-01-07 |
| CVE-2020-18494 |
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via c... |
Important |
hdf5 |
否 |
完成修复 |
2025-03-20 |
2026-01-05 |
| CVE-2020-18232 |
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via c... |
Moderate |
hdf5 |
是 |
完成修复 |
2025-03-20 |
2026-03-17 |
| CVE-2019-11139 |
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privile... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-03-20 |
2026-07-10 |
| CVE-2025-2368 |
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2025-03-19 |
2026-01-20 |
| CVE-2024-53589 |
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files... |
Moderate |
binutils |
否 |
完成修复 |
2025-03-18 |
2025-12-11 |
| CVE-2024-40635 |
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where... |
Moderate |
containerd |
是 |
完成修复 |
2025-03-18 |
2026-07-13 |
| CVE-2024-23226 |
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPa... |
Important |
webkitgtk4, webkitgtk3, webkit2gtk3 |
否 |
完成修复 |
2025-03-18 |
2025-12-29 |
| CVE-2019-9904 |
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agc... |
Moderate |
graphviz |
是 |
完成修复 |
2025-03-18 |
2026-03-27 |
| CVE-2019-9543 |
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Strea... |
Important |
poppler |
否 |
完成修复 |
2025-03-18 |
2026-01-04 |
| CVE-2019-18390 |
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest O... |
Important |
virglrenderer |
否 |
完成修复 |
2025-03-18 |
2025-12-30 |
| CVE-2019-18388 |
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of servic... |
Moderate |
virglrenderer |
是 |
完成修复 |
2025-03-18 |
2026-03-17 |
| CVE-2019-13164 |
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=b... |
Important |
virt:an, qemu, qemu-kvm-ma, qemu-kvm |
否 |
完成修复 |
2025-03-18 |
2025-12-05 |
| CVE-2019-11023 |
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonst... |
Important |
graphviz |
否 |
完成修复 |
2025-03-18 |
2026-01-04 |
| CVE-2019-1010004 |
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is:... |
Moderate |
sox |
是 |
完成修复 |
2025-03-18 |
2026-03-17 |
| CVE-2018-20030 |
An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to... |
Important |
libexif |
否 |
完成修复 |
2025-03-18 |
2026-01-06 |
| CVE-2025-24855 |
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modi... |
Important |
libxslt |
否 |
完成修复 |
2025-03-17 |
2026-01-05 |
| CVE-2025-24528 |
A flaw was found in krb5. With incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the... |
Moderate |
krb5 |
是 |
完成修复 |
2025-03-17 |
2026-06-24 |
| CVE-2025-24201 |
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionO... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2025-03-17 |
2026-01-04 |
| CVE-2025-2361 |
A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects... |
Moderate |
mercurial |
是 |
完成修复 |
2025-03-17 |
2026-06-24 |
| CVE-2024-8176 |
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML docum... |
Important |
xmlrpc-c, firefox, expat, thunderbird, lua-expat |
是 |
完成修复 |
2025-03-17 |
2026-01-06 |
| CVE-2024-55549 |
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
Important |
libxslt |
否 |
完成修复 |
2025-03-17 |
2026-01-04 |
| CVE-2024-27856 |
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2025-03-17 |
2026-01-04 |
| CVE-2024-26282 |
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vuln... |
Important |
firefox |
否 |
完成修复 |
2025-03-17 |
2025-12-29 |
| CVE-2024-10474 |
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links poten... |
Moderate |
firefox |
否 |
完成修复 |
2025-03-17 |
2026-01-20 |
| CVE-2020-16121 |
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype o... |
Low |
PackageKit |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2020-14393 |
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 char... |
Important |
perl-DBI |
否 |
完成修复 |
2025-03-17 |
2026-01-05 |
| CVE-2020-14392 |
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db... |
Moderate |
perl-DBI |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2020-14342 |
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject... |
Moderate |
cifs-utils |
是 |
完成修复 |
2025-03-17 |
2026-07-13 |
| CVE-2020-13987 |
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component wh... |
Important |
iscsi-initiator-utils |
否 |
完成修复 |
2025-03-17 |
2026-01-04 |
| CVE-2020-12278 |
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist beca... |
Low |
libgit2 |
否 |
完成修复 |
2025-03-17 |
2026-01-22 |
| CVE-2020-0499 |
In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow.... |
Moderate |
flac |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2019-2920 |
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected... |
Moderate |
mysql-connector-odbc, mysql, mysql:8.0 |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2019-20919 |
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and th... |
Moderate |
perl-DBI |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2019-19244 |
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has... |
Important |
sqlite |
否 |
完成修复 |
2025-03-17 |
2026-01-09 |
| CVE-2018-16301 |
The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vul... |
Moderate |
tcpdump |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2013-7491 |
An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires ... |
Moderate |
perl-DBI |
是 |
完成修复 |
2025-03-17 |
2026-03-17 |
| CVE-2025-21863 |
In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode i... |
Moderate |
kernel:5.10, kernel:4.19, kernel:6.6 |
否 |
完成修复 |
2025-03-15 |
2026-01-17 |
| CVE-2024-21204 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.... |
Moderate |
mysql |
是 |
完成修复 |
2025-03-14 |
2026-06-26 |
| CVE-2025-27788 |
JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document co... |
Important |
rubygem-json |
否 |
完成修复 |
2025-03-13 |
2026-01-04 |
| CVE-2025-23084 |
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. ... |
Moderate |
nodejs, nodejs:12, nodejs:14, nodejs:18, nodejs:10, nodejs:16, nodejs:20 |
是 |
完成修复 |
2025-03-13 |
2026-07-13 |
| CVE-2024-8929 |
In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to d... |
Moderate |
php |
是 |
完成修复 |
2025-03-13 |
2026-07-10 |
| CVE-2024-52616 |
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them... |
Moderate |
avahi |
是 |
完成修复 |
2025-03-13 |
2026-07-11 |
| CVE-2024-52615 |
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks w... |
Moderate |
avahi |
是 |
完成修复 |
2025-03-13 |
2026-07-11 |
| CVE-2024-39894 |
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) beca... |
Important |
openssh |
否 |
完成修复 |
2025-03-13 |
2026-01-09 |
| CVE-2024-39689 |
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the... |
Important |
python-certifi |
否 |
完成修复 |
2025-03-13 |
2026-01-04 |
| CVE-2024-2004 |
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would re... |
Moderate |
curl |
否 |
完成修复 |
2025-03-13 |
2026-01-05 |
| CVE-2024-11234 |
In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "re... |
Moderate |
php |
是 |
完成修复 |
2025-03-13 |
2026-07-10 |
| CVE-2024-11233 |
In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-de... |
Moderate |
php |
是 |
完成修复 |
2025-03-13 |
2026-07-10 |
| CVE-2021-32493 |
A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu f... |
Important |
djvulibre |
否 |
完成修复 |
2025-03-13 |
2025-12-29 |
| CVE-2021-32491 |
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file... |
Important |
djvulibre |
否 |
完成修复 |
2025-03-13 |
2025-12-29 |
| CVE-2021-32490 |
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file ma... |
Important |
djvulibre |
否 |
完成修复 |
2025-03-13 |
2025-12-29 |
| CVE-2019-6292 |
An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocP... |
Moderate |
yaml-cpp |
是 |
完成修复 |
2025-03-13 |
2026-03-17 |
| CVE-2019-6285 |
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial ... |
Moderate |
yaml-cpp |
是 |
完成修复 |
2025-03-13 |
2026-07-10 |
| CVE-2014-8161 |
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote au... |
Moderate |
postgresql |
否 |
完成修复 |
2025-03-13 |
2026-01-22 |
| CVE-2024-8096 |
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the s... |
Moderate |
curl |
否 |
完成修复 |
2025-03-12 |
2026-01-05 |
| CVE-2024-56161 |
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege ... |
Important |
linux-firmware |
否 |
完成修复 |
2025-03-12 |
2026-01-05 |
| CVE-2024-47814 |
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible i... |
Low |
vim |
是 |
完成修复 |
2025-03-12 |
2026-06-24 |
| CVE-2024-43802 |
Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in th... |
Low |
vim |
是 |
完成修复 |
2025-03-12 |
2026-06-24 |
| CVE-2024-43374 |
The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to t... |
Low |
vim |
是 |
完成修复 |
2025-03-12 |
2026-06-24 |
| CVE-2024-43168 |
DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet L... |
Moderate |
unbound |
是 |
完成修复 |
2025-03-12 |
2026-06-24 |
| CVE-2024-43167 |
DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet L... |
Low |
unbound |
是 |
完成修复 |
2025-03-12 |
2026-06-24 |
| CVE-2024-28047 |
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable infor... |
Moderate |
microcode_ctl |
是 |
完成修复 |
2025-03-12 |
2026-07-10 |
| CVE-2024-24582 |
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potenti... |
Important |
microcode_ctl |
否 |
完成修复 |
2025-03-12 |
2026-01-04 |
| CVE-2025-27363 |
An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related t... |
Important |
spice-client-win, java-17-openjdk, thunderbird, freetype, mingw-freetype, java-21-openjdk |
否 |
完成修复 |
2025-03-11 |
2025-12-05 |
| CVE-2024-9143 |
Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted \nexplicit values for the field polynomial can l... |
Moderate |
openssl |
否 |
完成修复 |
2025-03-11 |
2026-01-05 |
| CVE-2024-28607 |
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categ... |
Low |
iputils |
是 |
完成修复 |
2025-03-11 |
2026-07-09 |
| CVE-2023-50268 |
jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Versio... |
Moderate |
jq |
是 |
完成修复 |
2025-03-11 |
2026-03-27 |
| CVE-2023-46049 |
LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a cra... |
Moderate |
llvm |
是 |
完成修复 |
2025-03-11 |
2025-12-09 |
| CVE-2021-43540 |
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would n... |
Moderate |
firefox |
否 |
完成修复 |
2025-03-11 |
2026-01-20 |
| CVE-2020-10761 |
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw ... |
Moderate |
qemu, qemu-kvm |
否 |
完成修复 |
2025-03-11 |
2025-12-18 |
| CVE-2023-52971 |
MariaDB Server 10.10 through 10.11. and 11.0 through 11.4. crashes in JOIN::fix_all_splittings_in_plan. |
Moderate |
mariadb:10.3, mariadb, mariadb:10.5 |
是 |
完成修复 |
2025-03-09 |
2026-03-27 |
| CVE-2023-52970 |
MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., 11.0 through 11.0., and 11.1 through 11.4.* cra... |
Moderate |
mariadb:10.3, mariadb, mariadb:10.5 |
否 |
完成修复 |
2025-03-09 |
2026-01-08 |
| CVE-2023-52969 |
MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., and 11.0 through 11.0. can sometimes crash with... |
Moderate |
mariadb:10.3, mariadb, mariadb:10.5 |
是 |
完成修复 |
2025-03-09 |
2026-06-24 |
| CVE-2023-52968 |
MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11... |
Moderate |
mariadb:10.3, mariadb, mariadb:10.5 |
是 |
完成修复 |
2025-03-09 |
2026-06-24 |
| CVE-2024-57849 |
In the Linux kernel, the following vulnerability has been resolved: \n \ns390/cpum_sf: Handle CPU hotplug remove during samplin... |
Important |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2025-03-08 |
2025-12-08 |
| CVE-2025-27221 |
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of auth... |
Low |
ruby, ruby:3.3 |
是 |
完成修复 |
2025-03-07 |
2026-07-10 |
| CVE-2025-26623 |
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A h... |
Moderate |
exiv2, compat-exiv2-026, compat-exiv2-023 |
是 |
完成修复 |
2025-03-07 |
2026-07-11 |
| CVE-2025-26601 |
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one ... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26600 |
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that ... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26599 |
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it can... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26598 |
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device ba... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26597 |
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the k... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26596 |
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is wr... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26595 |
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the sta... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-26594 |
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a... |
Important |
xorg-x11-server-Xwayland, xorg-x11-server, tigervnc |
否 |
完成修复 |
2025-03-07 |
2025-12-29 |
| CVE-2025-25186 |
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior ... |
Moderate |
ruby, ruby:3.3 |
是 |
完成修复 |
2025-03-07 |
2026-06-24 |
| CVE-2025-24928 |
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit... |
Important |
libxml2 |
否 |
完成修复 |
2025-03-07 |
2026-01-09 |
| CVE-2025-23090 |
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not l... |
Important |
nodejs |
否 |
完成修复 |
2025-03-07 |
2026-01-06 |
| CVE-2025-21567 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that a... |
Moderate |
mysql |
是 |
完成修复 |
2025-03-07 |
2026-06-26 |
| CVE-2025-21566 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... |
Moderate |
mysql |
是 |
完成修复 |
2025-03-07 |
2026-06-26 |
| CVE-2025-21499 |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... |
Moderate |
mysql |
是 |
完成修复 |
2025-03-07 |
2026-06-24 |