CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-47627 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problem... Important python-aiohttp 完成修复 2024-10-24 2026-01-04
CVE-2023-47248 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code executi... Critical python-arrow 完成修复 2024-10-24 2026-01-10
CVE-2023-47039 A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment vari... Important perl-Test-Compile 完成修复 2024-10-24 2026-01-04
CVE-2023-46751 An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote a... Important ghostscript 完成修复 2024-10-24 2026-01-06
CVE-2023-46228 zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/... Important zchunk 完成修复 2024-10-24 2025-12-13
CVE-2023-44431 BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-ad... Important bluez 完成修复 2024-10-24 2026-01-05
CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer... Important composer 完成修复 2024-10-24 2026-01-07
CVE-2023-41064 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS... Important libwebp 完成修复 2024-10-24 2026-01-05
CVE-2023-39810 An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. Important busybox 完成修复 2024-10-24 2026-01-05
CVE-2023-39616 AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1... Important aom 完成修复 2024-10-24 2026-01-06
CVE-2023-39135 An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry. Important zip 完成修复 2024-10-24 2026-01-04
CVE-2023-37536 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP reques... Important xerces-c 完成修复 2024-10-24 2026-01-04
CVE-2023-37463 cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax wit... Important python-cmarkgfm 完成修复 2024-10-24 2026-01-04
CVE-2023-37329 GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote att... Important gstreamer1-plugins-bad-free 完成修复 2024-10-24 2026-01-04
CVE-2023-37276 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llh... Important python-aiohttp 完成修复 2024-10-24 2026-01-04
CVE-2023-37212 Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-10-24 2025-12-30
CVE-2023-37209 A use-after-free condition existed in NotifyOnHistoryReload where a LoadingSessionHistoryEntry object was freed and a refer... Important firefox 完成修复 2024-10-24 2025-12-30
CVE-2023-37203 Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to trick ... Important firefox 完成修复 2024-10-24 2025-12-30
CVE-2023-3676 A security issue was discovered in Kubernetes where a user \n that can create pods on Windows nodes may be able to escalate to ... Important kubernetes 完成修复 2024-10-24 2025-12-29
CVE-2023-3592 In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid... Important mosquitto 完成修复 2024-10-24 2026-01-08
CVE-2023-32182 A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 pos... Important postfix 完成修复 2024-10-24 2026-01-04
CVE-2023-31654 Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /op... Critical redis 完成修复 2024-10-24 2026-01-07
CVE-2023-30585 A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users wh... Important nodejs 完成修复 2024-10-24 2026-01-06
CVE-2023-28366 The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sen... Important mosquitto 完成修复 2024-10-24 2025-12-29
CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows net... Important bluez 完成修复 2024-10-24 2026-01-05
CVE-2023-25266 An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory s... Important python-tornado 完成修复 2024-10-24 2026-01-04
CVE-2023-23583 Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to... Important microcode_ctl 完成修复 2024-10-24 2026-01-05
CVE-2023-1668 A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without... Important openvswitch 完成修复 2024-10-24 2026-01-05
CVE-2022-48541 A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -... Important ImageMagick 完成修复 2024-10-24 2026-01-05
CVE-2022-46884 A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. Thi... Important firefox 完成修复 2024-10-24 2025-12-30
CVE-2022-43358 Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g21021... Important libsass 完成修复 2024-10-24 2026-01-05
CVE-2022-41678 Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. \n \nIn details, in ActiveMQ c... Important jetty 完成修复 2024-10-24 2026-01-06
CVE-2022-39177 BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities... Important bluez 完成修复 2024-10-24 2026-01-05
CVE-2024-9050 A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sani... Important NetworkManager-libreswan 完成修复 2024-10-23 2025-12-30
CVE-2024-47875 Important grafana, grafana-pcp 完成修复 2024-10-23 2026-01-04
CVE-2024-29039 tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate... Low tpm2-tools 完成修复 2024-10-22 2026-07-09
CVE-2024-29038 tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary... Low tpm2-tools 完成修复 2024-10-22 2026-07-09
CVE-2024-27834 The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS ... Important webkitgtk, webkit2gtk3 完成修复 2024-10-22 2026-01-04
CVE-2024-2757 In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-spac... Moderate php 完成修复 2024-10-22 2026-07-10
CVE-2024-26142 Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header p... Moderate ruby 完成修复 2024-10-22 2026-07-09
CVE-2024-25450 imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts(). Important imlib2 完成修复 2024-10-22 2026-01-05
CVE-2024-25448 An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via par... Important imlib2 完成修复 2024-10-22 2026-01-05
CVE-2024-25447 An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow v... Important imlib2 完成修复 2024-10-22 2026-01-05
CVE-2024-24821 Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory ar... Important composer 完成修复 2024-10-22 2026-01-04
CVE-2024-24576 Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77... Critical rust 完成修复 2024-10-22 2025-12-16
CVE-2024-24557 Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone... Moderate docker, moby 完成修复 2024-10-22 2026-03-18
CVE-2024-24474 QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer l... Important qemu 完成修复 2024-10-22 2025-12-10
CVE-2024-22563 openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c. Important openvswitch 完成修复 2024-10-22 2026-01-05
CVE-2024-1272 Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedd... Important cockpit 完成修复 2024-10-22 2026-01-08
CVE-2024-0444 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... Important gstreamer1, gstreamer1-plugins-bad-free 完成修复 2024-10-22 2025-12-29
CVE-2023-6873 Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-10-22 2025-12-30
CVE-2023-6866 TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArra... Important firefox 完成修复 2024-10-22 2025-12-30
CVE-2023-6704 Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corrup... Important libavif 完成修复 2024-10-22 2026-01-06
CVE-2023-6360 The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from... Important wordpress 完成修复 2024-10-22 2026-01-04
CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-10-22 2025-12-30
CVE-2023-5632 In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes t... Important mosquitto 完成修复 2024-10-22 2025-12-29
CVE-2023-5625 A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resultin... Important python-eventlet 完成修复 2024-10-22 2026-01-04
CVE-2023-5528 A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be ... Important kubernetes 完成修复 2024-10-22 2025-12-29
CVE-2023-5214 In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. Critical bolt 完成修复 2024-10-22 2026-01-04
CVE-2023-52134 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my Word... Important wordpress 完成修复 2024-10-22 2026-01-04
CVE-2023-5175 During process shutdown, it was possible that an ImageBitmap was created that would later be used after being freed from a di... Critical firefox 完成修复 2024-10-22 2026-01-04
CVE-2023-5173 In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under in... Important firefox 完成修复 2024-10-22 2025-12-30
CVE-2023-5172 A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-af... Critical firefox 完成修复 2024-10-22 2026-01-04
CVE-2023-5170 In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak... Important firefox 完成修复 2024-10-22 2025-12-30
CVE-2023-51257 An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. Important jasper 完成修复 2024-10-22 2026-01-06
CVE-2023-51107 A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of ... Important mupdf 完成修复 2024-10-22 2026-01-07
CVE-2023-51106 A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of... Important mupdf 完成修复 2024-10-22 2026-01-07
CVE-2023-51105 A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle... Important mupdf 完成修复 2024-10-22 2026-01-07
CVE-2023-51104 A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_im... Important mupdf 完成修复 2024-10-22 2026-01-07
CVE-2023-51103 A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fznew_pixmap... Important mupdf 完成修复 2024-10-22 2026-01-07
CVE-2023-50782 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS... Important python-cryptography 完成修复 2024-10-22 2026-01-04
CVE-2023-50472 cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. Important cjson 完成修复 2024-10-22 2026-01-08
CVE-2023-50471 cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. Important cjson 完成修复 2024-10-22 2026-01-08
CVE-2023-5044 Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. Important nginx 完成修复 2024-10-22 2026-01-06
CVE-2023-5043 Ingress nginx annotation injection causes arbitrary command execution. Important nginx 完成修复 2024-10-22 2026-01-06
CVE-2023-50230 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netwo... Important bluez 完成修复 2024-10-22 2026-01-05
CVE-2023-50229 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netwo... Important bluez 完成修复 2024-10-22 2026-01-05
CVE-2023-49569 A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to creat... Critical grafana 完成修复 2024-10-22 2026-01-10
CVE-2023-49568 A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker... Important grafana 完成修复 2024-10-22 2026-01-04
CVE-2023-49355 decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE... Important jq 完成修复 2024-10-22 2026-01-06
CVE-2023-49288 Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-A... Important squid:4, squid 完成修复 2024-10-22 2026-01-04
CVE-2023-49210 The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its ... Critical openssl1.1 完成修复 2024-10-22 2026-01-10
CVE-2024-47666 In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-47665 In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI ... Low kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-24
CVE-2024-47664 In the Linux kernel, the following vulnerability has been resolved: spi: hisi-kunpeng: Add verification for the max_frequenc... Low kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-24
CVE-2024-47662 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagno... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-10-21 2026-01-21
CVE-2024-47661 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-10-21 2026-01-21
CVE-2024-47658 In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled T... Low kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-24
CVE-2024-46871 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Correct the defined value for AMDGPU_DM... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46870 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout for DCN35 [Why... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-10-21 2026-01-21
CVE-2024-46843 In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If ho... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46842 In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-10-21 2026-01-21
CVE-2024-46836 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: validate endpoint index for ast... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46835 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix smatch static checker warning adev-&g... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46833 In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num ... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46827 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix firmware crash due to invalid peer nss... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46826 In the Linux kernel, the following vulnerability has been resolved: ELF: fix kernel.randomize_va_space double read ELF lo... Moderate kernel 完成修复 2024-10-21 2026-01-21
CVE-2024-46821 In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix negative array index read Avoid using... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21
CVE-2024-46820 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend\n... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-10-21 2026-01-21
CVE-2024-46816 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Stop amdgpu_dm initialize when link num... Moderate kernel:5.10, kernel:4.19 完成修复 2024-10-21 2026-01-21

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""