CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-32731 When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPAC... Important grpc 完成修复 2024-11-24 2026-01-04
CVE-2023-32216 Memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with en... Critical firefox 完成修复 2024-11-24 2026-01-04
CVE-2023-32209 A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113. Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2023-3217 Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corrupti... Important qt5-qtwebengine 完成修复 2024-11-24 2026-01-04
CVE-2023-3216 Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption ... Important qt5-qtwebengine 完成修复 2024-11-24 2026-01-04
CVE-2023-3215 Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corrupt... Important qt5-qtwebengine 完成修复 2024-11-24 2026-01-04
CVE-2023-31724 yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. Important yasm 完成修复 2024-11-24 2026-01-04
CVE-2023-31102 Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. Important p7zip 完成修复 2024-11-24 2025-12-30
CVE-2023-30513 Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in t... Important kubernetes 完成修复 2024-11-24 2026-01-06
CVE-2023-29551 Mozilla developers Randell Jesup, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs p... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2023-29543 An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's ... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2023-29537 Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled co... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2023-29534 Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to ... Critical firefox 完成修复 2024-11-24 2026-01-04
CVE-2023-28161 If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2023-26485 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity ... Important python-cmarkgfm 完成修复 2024-11-24 2026-01-04
CVE-2023-2618 A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by th... Important opencv 完成修复 2024-11-24 2025-12-06
CVE-2023-2617 A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability ... Important opencv 完成修复 2024-11-24 2025-12-06
CVE-2023-25674 TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in Random... Important tensorflow 完成修复 2024-11-24 2026-01-04
CVE-2023-25671 TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes.... Important tensorflow 完成修复 2024-11-24 2026-01-04
CVE-2023-25666 TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exce... Important tensorflow 完成修复 2024-11-24 2026-01-04
CVE-2023-25665 TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when SparseSparseMaximum is ... Important tensorflow 完成修复 2024-11-24 2026-01-04
CVE-2023-25662 TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overf... Important tensorflow 完成修复 2024-11-24 2026-01-04
CVE-2023-24824 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity ... Important pandoc, python-cmarkgfm 完成修复 2024-11-24 2025-12-29
CVE-2023-24816 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally develop... Important ipython 完成修复 2024-11-24 2026-01-06
CVE-2023-24580 An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. P... Important python-django 完成修复 2024-11-24 2026-01-04
CVE-2023-23969 In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in... Important python-django 完成修复 2024-11-24 2026-01-04
CVE-2023-22551 The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a den... Important ftp 完成修复 2024-11-24 2026-01-07
CVE-2023-22486 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.... Important python-cmarkgfm 完成修复 2024-11-24 2026-01-04
CVE-2023-22484 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.... Important python-cmarkgfm 完成修复 2024-11-24 2026-01-04
CVE-2023-22483 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.... Important python-cmarkgfm 完成修复 2024-11-24 2026-01-04
CVE-2022-47630 Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downst... Important arm-trusted-firmware 完成修复 2024-11-24 2026-01-06
CVE-2022-46885 Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-46879 Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported ... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-46873 Because Firefox did not implement the unsafe-hashes CSP directive, an attacker who was able to inject markup into ... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-45415 When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may hav... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-45407 If an attacker loaded a font using FontFace() on a background worker, a use-after-free could have occurred, leadin... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-44940 Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc. Critical patchelf 完成修复 2024-11-24 2026-01-09
CVE-2022-42930 If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the ThirdPartyUtil com... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-40320 cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. Important libconfuse 完成修复 2024-11-24 2026-01-08
CVE-2022-39286 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains ... Important python-jupyter-core 完成修复 2024-11-24 2026-01-04
CVE-2022-38928 XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38238 XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38237 XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38236 XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38231 XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38229 XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.... Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38228 XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38227 XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-38222 There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending ... Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2022-35414 softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or... Important qemu, qemu-kvm:a8 完成修复 2024-11-24 2025-12-08
CVE-2022-32912 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadO... Important webkitgtk, webkit2gtk3 完成修复 2024-11-24 2025-12-29
CVE-2022-32547 In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', wh... Important ImageMagick 完成修复 2024-11-24 2026-01-05
CVE-2022-32546 A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coder... Important ImageMagick 完成修复 2024-11-24 2026-01-05
CVE-2022-32545 A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coder... Important ImageMagick 完成修复 2024-11-24 2026-01-05
CVE-2022-32200 libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. Important libdwarf 完成修复 2024-11-24 2026-01-06
CVE-2022-32166 In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks�... Important openvswitch 完成修复 2024-11-24 2026-01-05
CVE-2022-30790 Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. Important uboot-tools 完成修复 2024-11-24 2025-12-30
CVE-2022-30065 A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafte... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2022-29918 Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 9... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-29241 Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyte... Important python-jupyter-server 完成修复 2024-11-24 2026-01-04
CVE-2022-28391 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value t... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2022-28288 Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety b... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-28284 SVG's <use> element could have been used to load unexpected content that could have executed script in certa... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-26488 In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The instal... Important python3 完成修复 2024-11-24 2026-01-09
CVE-2022-26061 A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted... Important hdf5 完成修复 2024-11-24 2026-01-05
CVE-2022-25972 An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF f... Important hdf5 完成修复 2024-11-24 2026-01-05
CVE-2022-25942 An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF fi... Important hdf5 完成修复 2024-11-24 2026-01-05
CVE-2022-24106 In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first sca... Important poppler 完成修复 2024-11-24 2026-01-04
CVE-2022-2309 NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is u... Important libxml2 完成修复 2024-11-24 2026-01-09
CVE-2022-22758 When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. ... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-22755 By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScri... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-22752 Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs sho... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-22736 If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the curr... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-21797 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() c... Critical python-joblib 完成修复 2024-11-24 2026-01-09
CVE-2022-21699 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally develop... Important ipython 完成修复 2024-11-24 2026-01-06
CVE-2022-2120 OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an atta... Critical dcmtk 完成修复 2024-11-24 2026-01-04
CVE-2022-2119 OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker ... Critical dcmtk 完成修复 2024-11-24 2026-01-04
CVE-2022-1920 Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while pa... Important gstreamer1-plugins-good 完成修复 2024-11-24 2026-01-05
CVE-2022-1887 The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101... Critical firefox 完成修复 2024-11-24 2026-01-04
CVE-2022-0843 Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some ... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2022-0511 Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2021-42386 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-42384 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-42383 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-42382 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-42379 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-42378 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk p... Important busybox 完成修复 2024-11-24 2026-01-05
CVE-2021-40226 xpdfreader 4.03 is vulnerable to Buffer Overflow. Important poppler 完成修复 2024-11-24 2026-01-04
CVE-2021-38499 Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption a... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2021-38494 Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption a... Important firefox 完成修复 2024-11-24 2025-12-29
CVE-2021-38094 Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to ca... Important ffmpeg 完成修复 2024-11-24 2025-12-06
CVE-2021-38093 Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to c... Important ffmpeg 完成修复 2024-11-24 2025-12-06
CVE-2021-38092 Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to ... Important ffmpeg 完成修复 2024-11-24 2025-12-06
CVE-2021-38091 Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to ... Important ffmpeg 完成修复 2024-11-24 2025-12-06
CVE-2021-38090 Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers t... Important ffmpeg 完成修复 2024-11-24 2025-12-06
CVE-2021-3682 A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets... Important qemu, qemu-kvm 完成修复 2024-11-24 2025-12-10
CVE-2021-36493 Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. Important xpdf 完成修复 2024-11-24 2026-01-04
CVE-2021-36090 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an... Important apache-commons-compress 完成修复 2024-11-24 2026-01-06
CVE-2021-35517 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an... Important apache-commons-compress 完成修复 2024-11-24 2026-01-06
CVE-2021-35516 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an ... Important apache-commons-compress 完成修复 2024-11-24 2026-01-06

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""