CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2021-31239 An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c functi... Important sqlite 完成修复 2025-03-20 2026-01-09
CVE-2021-20299 A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trig... Low OpenEXR 完成修复 2025-03-20 2026-03-18
CVE-2020-36773 Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) bec... Important ghostscript 完成修复 2025-03-20 2026-01-06
CVE-2020-36138 An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial o... Important ffmpeg 完成修复 2025-03-20 2025-12-06
CVE-2020-35498 A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious ... Moderate openvswitch 完成修复 2025-03-20 2026-03-18
CVE-2020-24742 An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, a... Moderate qt, qt5 完成修复 2025-03-20 2026-03-18
CVE-2020-24165 An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges... Important qemu, qemu-kvm 完成修复 2025-03-20 2025-12-10
CVE-2020-21427 Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run... Important freeimage 完成修复 2025-03-20 2026-01-07
CVE-2020-21426 Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run a... Important freeimage 完成修复 2025-03-20 2026-01-07
CVE-2020-18494 Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via c... Important hdf5 完成修复 2025-03-20 2026-01-05
CVE-2020-18232 Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via c... Moderate hdf5 完成修复 2025-03-20 2026-03-17
CVE-2019-11139 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privile... Moderate microcode_ctl 完成修复 2025-03-20 2026-07-10
CVE-2025-2368 A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::... Moderate firefox, thunderbird 完成修复 2025-03-19 2026-01-20
CVE-2024-53589 GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files... Moderate binutils 完成修复 2025-03-18 2025-12-11
CVE-2024-40635 containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where... Moderate containerd 完成修复 2025-03-18 2026-07-13
CVE-2024-23226 The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPa... Important webkitgtk4, webkitgtk3, webkit2gtk3 完成修复 2025-03-18 2025-12-29
CVE-2019-9904 An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agc... Moderate graphviz 完成修复 2025-03-18 2026-03-27
CVE-2019-9543 An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Strea... Important poppler 完成修复 2025-03-18 2026-01-04
CVE-2019-18390 An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest O... Important virglrenderer 完成修复 2025-03-18 2025-12-30
CVE-2019-18388 A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of servic... Moderate virglrenderer 完成修复 2025-03-18 2026-03-17
CVE-2019-13164 qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=b... Important virt:an, qemu, qemu-kvm-ma, qemu-kvm 完成修复 2025-03-18 2025-12-05
CVE-2019-11023 The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonst... Important graphviz 完成修复 2025-03-18 2026-01-04
CVE-2019-1010004 SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is:... Moderate sox 完成修复 2025-03-18 2026-03-17
CVE-2018-20030 An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to... Important libexif 完成修复 2025-03-18 2026-01-06
CVE-2025-24855 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modi... Important libxslt 完成修复 2025-03-17 2026-01-05
CVE-2025-24528 A flaw was found in krb5. With incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the... Moderate krb5 完成修复 2025-03-17 2026-06-24
CVE-2025-24201 An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionO... Important webkit2gtk3 完成修复 2025-03-17 2026-01-04
CVE-2025-2361 A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects... Moderate mercurial 完成修复 2025-03-17 2026-06-24
CVE-2024-8176 A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML docum... Important xmlrpc-c, firefox, expat, thunderbird, lua-expat 完成修复 2025-03-17 2026-01-06
CVE-2024-55549 xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. Important libxslt 完成修复 2025-03-17 2026-01-04
CVE-2024-27856 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17... Important webkitgtk, webkit2gtk3 完成修复 2025-03-17 2026-01-04
CVE-2024-26282 Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vuln... Important firefox 完成修复 2025-03-17 2025-12-29
CVE-2024-10474 Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links poten... Moderate firefox 完成修复 2025-03-17 2026-01-20
CVE-2020-16121 PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype o... Low PackageKit 完成修复 2025-03-17 2026-03-17
CVE-2020-14393 A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 char... Important perl-DBI 完成修复 2025-03-17 2026-01-05
CVE-2020-14392 An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db... Moderate perl-DBI 完成修复 2025-03-17 2026-03-17
CVE-2020-14342 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject... Moderate cifs-utils 完成修复 2025-03-17 2026-07-13
CVE-2020-13987 An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component wh... Important iscsi-initiator-utils 完成修复 2025-03-17 2026-01-04
CVE-2020-12278 An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist beca... Low libgit2 完成修复 2025-03-17 2026-01-22
CVE-2020-0499 In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow.... Moderate flac 完成修复 2025-03-17 2026-03-17
CVE-2019-2920 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected... Moderate mysql-connector-odbc, mysql, mysql:8.0 完成修复 2025-03-17 2026-03-17
CVE-2019-20919 An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and th... Moderate perl-DBI 完成修复 2025-03-17 2026-03-17
CVE-2019-19244 sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has... Important sqlite 完成修复 2025-03-17 2026-01-09
CVE-2018-16301 The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vul... Moderate tcpdump 完成修复 2025-03-17 2026-03-17
CVE-2013-7491 An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires ... Moderate perl-DBI 完成修复 2025-03-17 2026-03-17
CVE-2025-21863 In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode i... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2025-03-15 2026-01-17
CVE-2024-21204 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.... Moderate mysql 完成修复 2025-03-14 2026-06-26
CVE-2025-27788 JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document co... Important rubygem-json 完成修复 2025-03-13 2026-01-04
CVE-2025-23084 A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. ... Moderate nodejs, nodejs:12, nodejs:14, nodejs:18, nodejs:10, nodejs:16, nodejs:20 完成修复 2025-03-13 2026-07-13
CVE-2024-8929 In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to d... Moderate php 完成修复 2025-03-13 2026-07-10
CVE-2024-52616 A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them... Moderate avahi 完成修复 2025-03-13 2026-07-11
CVE-2024-52615 A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks w... Moderate avahi 完成修复 2025-03-13 2026-07-11
CVE-2024-39894 OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) beca... Important openssh 完成修复 2025-03-13 2026-01-09
CVE-2024-39689 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the... Important python-certifi 完成修复 2025-03-13 2026-01-04
CVE-2024-2004 When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would re... Moderate curl 完成修复 2025-03-13 2026-01-05
CVE-2024-11234 In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "re... Moderate php 完成修复 2025-03-13 2026-07-10
CVE-2024-11233 In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-de... Moderate php 完成修复 2025-03-13 2026-07-10
CVE-2021-32493 A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu f... Important djvulibre 完成修复 2025-03-13 2025-12-29
CVE-2021-32491 A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file... Important djvulibre 完成修复 2025-03-13 2025-12-29
CVE-2021-32490 A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file ma... Important djvulibre 完成修复 2025-03-13 2025-12-29
CVE-2019-6292 An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocP... Moderate yaml-cpp 完成修复 2025-03-13 2026-03-17
CVE-2019-6285 The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial ... Moderate yaml-cpp 完成修复 2025-03-13 2026-07-10
CVE-2014-8161 PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote au... Moderate postgresql 完成修复 2025-03-13 2026-01-22
CVE-2024-8096 When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the s... Moderate curl 完成修复 2025-03-12 2026-01-05
CVE-2024-56161 Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege ... Important linux-firmware 完成修复 2025-03-12 2026-01-05
CVE-2024-47814 Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible i... Low vim 完成修复 2025-03-12 2026-06-24
CVE-2024-43802 Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in th... Low vim 完成修复 2025-03-12 2026-06-24
CVE-2024-43374 The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to t... Low vim 完成修复 2025-03-12 2026-06-24
CVE-2024-43168 DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet L... Moderate unbound 完成修复 2025-03-12 2026-06-24
CVE-2024-43167 DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet L... Low unbound 完成修复 2025-03-12 2026-06-24
CVE-2024-28047 Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable infor... Moderate microcode_ctl 完成修复 2025-03-12 2026-07-10
CVE-2024-24582 Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potenti... Important microcode_ctl 完成修复 2025-03-12 2026-01-04
CVE-2025-27363 An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related t... Important spice-client-win, java-17-openjdk, thunderbird, freetype, mingw-freetype, java-21-openjdk 完成修复 2025-03-11 2025-12-05
CVE-2024-9143 Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted \nexplicit values for the field polynomial can l... Moderate openssl 完成修复 2025-03-11 2026-01-05
CVE-2024-28607 The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categ... Low iputils 完成修复 2025-03-11 2026-07-09
CVE-2023-50268 jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Versio... Moderate jq 完成修复 2025-03-11 2026-03-27
CVE-2023-46049 LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a cra... Moderate llvm 完成修复 2025-03-11 2025-12-09
CVE-2021-43540 WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would n... Moderate firefox 完成修复 2025-03-11 2026-01-20
CVE-2020-10761 An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw ... Moderate qemu, qemu-kvm 完成修复 2025-03-11 2025-12-18
CVE-2023-52971 MariaDB Server 10.10 through 10.11. and 11.0 through 11.4. crashes in JOIN::fix_all_splittings_in_plan. Moderate mariadb:10.3, mariadb, mariadb:10.5 完成修复 2025-03-09 2026-03-27
CVE-2023-52970 MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., 11.0 through 11.0., and 11.1 through 11.4.* cra... Moderate mariadb:10.3, mariadb, mariadb:10.5 完成修复 2025-03-09 2026-01-08
CVE-2023-52969 MariaDB Server 10.4 through 10.5., 10.6 through 10.6., 10.7 through 10.11., and 11.0 through 11.0. can sometimes crash with... Moderate mariadb:10.3, mariadb, mariadb:10.5 完成修复 2025-03-09 2026-06-24
CVE-2023-52968 MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11... Moderate mariadb:10.3, mariadb, mariadb:10.5 完成修复 2025-03-09 2026-06-24
CVE-2024-57849 In the Linux kernel, the following vulnerability has been resolved: \n \ns390/cpum_sf: Handle CPU hotplug remove during samplin... Important kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2025-03-08 2025-12-08
CVE-2025-27221 In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of auth... Low ruby, ruby:3.3 完成修复 2025-03-07 2026-07-10
CVE-2025-26623 Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A h... Moderate exiv2, compat-exiv2-026, compat-exiv2-023 完成修复 2025-03-07 2026-07-11
CVE-2025-26601 A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one ... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26600 A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that ... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26599 An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it can... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26598 An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device ba... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26597 A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the k... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26596 A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is wr... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26595 A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the sta... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-26594 A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2025-03-07 2025-12-29
CVE-2025-25186 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior ... Moderate ruby, ruby:3.3 完成修复 2025-03-07 2026-06-24
CVE-2025-24928 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit... Important libxml2 完成修复 2025-03-07 2026-01-09
CVE-2025-23090 With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not l... Important nodejs 完成修复 2025-03-07 2026-01-06
CVE-2025-21567 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that a... Moderate mysql 完成修复 2025-03-07 2026-06-26
CVE-2025-21566 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql 完成修复 2025-03-07 2026-06-26
CVE-2025-21499 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql 完成修复 2025-03-07 2026-06-24

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""