CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2024-5197 There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w,... Important libvpx 完成修复 2024-09-20 2026-01-05
CVE-2024-45770 Moderate pcp 完成修复 2024-09-20 2026-03-18
CVE-2024-45769 Moderate pcp 完成修复 2024-09-20 2026-03-18
CVE-2024-36952 In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to ... Moderate kernel 完成修复 2024-09-20 2026-01-22
CVE-2024-36924 In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Release hbalock before calling lpfc_worker_w... Moderate kernel 完成修复 2024-09-20 2026-01-22
CVE-2024-35962 In the Linux kernel, the following vulnerability has been resolved:\nnetfilter: complete validation of user input\nIn my recent... Moderate kernel 完成修复 2024-09-20 2026-01-22
CVE-2023-6349 A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured siz... Moderate libvpx 完成修复 2024-09-20 2026-01-25
CVE-2024-8394 Important thunderbird 完成修复 2024-09-18 2026-01-04
CVE-2024-8387 Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2024-09-18 2025-12-30
CVE-2024-8386 If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another sit... Low firefox, thunderbird 完成修复 2024-09-18 2026-01-24
CVE-2024-8385 A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vuln... Important firefox, thunderbird 完成修复 2024-09-18 2025-12-30
CVE-2024-8384 The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point b... Moderate firefox, thunderbird 完成修复 2024-09-18 2026-01-24
CVE-2024-8383 Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the br... Moderate firefox 完成修复 2024-09-18 2026-01-24
CVE-2024-8382 Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those eve... Moderate firefox, thunderbird 完成修复 2024-09-18 2026-01-24
CVE-2024-8381 A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `wit... Important firefox, thunderbird 完成修复 2024-09-18 2025-12-30
CVE-2024-7652 An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leadin... Important firefox, thunderbird 完成修复 2024-09-18 2025-12-30
CVE-2024-41946 REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expans... Low ruby, pcs, pcsc-lite-ccid, ruby:3.3 完成修复 2024-09-18 2026-03-18
CVE-2024-41123 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many s... Moderate ruby, pcs, pcsc-lite-ccid, ruby:3.3 完成修复 2024-09-18 2026-07-09
CVE-2023-52323 PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. Moderate fence-agents, resource-agents 完成修复 2024-09-12 2026-07-11
CVE-2023-42833 A vulnerability was found in WebKitGTK. This flaw allows a remote attacker to trigger arbitrary code execution by persuading a ... Important webkitgtk, webkit2gtk3 完成修复 2024-09-12 2026-01-04
CVE-2022-46725 A vulnerability was found in WebKitGTK. This flaw occurs due to an issue in the component URL Handler, which allows a remote at... Moderate webkitgtk, webkit2gtk3 完成修复 2024-09-12 2026-03-18
CVE-2022-46705 A vulnerability was found in WebKitGTK. This flaw allows a remote attacker to bypass security restrictions and spoof the user's... Moderate webkit2gtk3 完成修复 2024-09-12 2026-07-12
CVE-2022-32933 A flaw was found in webkitgtk where a website may be able to track the websites a user visited in private browsing mode. Moderate webkitgtk, webkit2gtk3 完成修复 2024-09-12 2026-03-18
CVE-2022-32919 A vulnerability was found in WebKitGTK and WPE WebKit that allows a remote attacker to conduct spoofing attacks by exploiting i... Moderate webkit2gtk3 完成修复 2024-09-12 2026-07-11
CVE-2024-34397 An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes ... Moderate glib2 完成修复 2024-09-10 2026-07-13
CVE-2024-4467 A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a json:{} ... Important virt-what, virt:an, qemu-kvm, qemu 完成修复 2024-09-06 2025-12-12
CVE-2024-38095 .NET and Visual Studio Denial of Service Vulnerability Moderate dotnet6.0 完成修复 2024-09-06 2025-12-05
CVE-2024-35264 .NET and Visual Studio Remote Code Execution Vulnerability Important dotnet6.0 完成修复 2024-09-06 2025-12-05
CVE-2024-30105 .NET and Visual Studio Denial of Service Vulnerability Important dotnet6.0 完成修复 2024-09-06 2025-12-05
CVE-2024-25082 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. Moderate fontforge 完成修复 2024-09-06 2026-07-11
CVE-2024-25081 Splinefont in FontForge through 20230101 allows command injection via crafted filenames. Moderate fontforge 完成修复 2024-09-06 2026-07-11
CVE-2021-47501 In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL pointer dereference in i40e_dbg_dump_desc... Moderate kernel 完成修复 2024-09-06 2026-01-22
CVE-2024-42472 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or comp... Important bubblewrap, [a8]flatpak-xdg-utils, flatpak 完成修复 2024-09-05 2026-01-05
CVE-2024-8389 Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-09-03 2025-12-30
CVE-2024-8088 There is a HIGH severity vulnerability affecting the CPython "zipfile"\nmodule affecting "zipfile.Path". Note that the more com... Moderate python3, python39:3.9, python, python3.11 完成修复 2024-09-02 2026-07-10
CVE-2024-7348 Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL fu... Important postgresql:13, postgresql:12, postgresql, postgresql:15 完成修复 2024-09-02 2026-01-04
CVE-2024-6923 There is a MEDIUM severity vulnerability affecting CPython.\nThe \nemail module didn’t properly quote newlines for email head... Moderate python3, python39:3.9, python, python3.11 完成修复 2024-09-02 2026-07-10
CVE-2024-4317 Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to ... Low postgresql:15, postgresql 完成修复 2024-09-02 2026-03-18
CVE-2024-4032 The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “... Low python3, python39:3.9, python, python3.11 完成修复 2024-09-02 2026-06-24
CVE-2024-37891 urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with ProxyManager, the `Proxy-A... Moderate python-urllib3, python3.11-urllib3, fence-agents, resource-agents 完成修复 2024-08-30 2026-06-24
CVE-2024-24788 A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop. Important grafana, go-toolset:an8, runc, skopeo, containernetworking-plugins, container-tools:an8, git-lfs, golang, grafana-pcp 完成修复 2024-08-30 2025-12-10
CVE-2024-2398 When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpass... Important curl 完成修复 2024-08-30 2026-01-05
CVE-2024-1298 EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflo... Moderate edk2 完成修复 2024-08-30 2026-07-13
CVE-2024-36137 A flaw was found in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. The N... Low nodejs, nodejs:20 完成修复 2024-08-29 2026-03-18
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder ... Moderate nodejs:18, nodejs, nodejs:20 完成修复 2024-08-29 2026-03-18
CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrictions.\nBy embedding non-network imports in data URLs, an ... Moderate nodejs:18, nodejs, nodejs:20 完成修复 2024-08-29 2026-06-25
CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read f... Low nodejs, nodejs:20 完成修复 2024-08-29 2026-03-18
CVE-2024-4076 Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an ... Important bind9.16, bind 完成修复 2024-08-27 2026-01-06
CVE-2024-38428 url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure be... Moderate wget 完成修复 2024-08-27 2026-07-13
CVE-2024-1737 Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can ... Important bind9.16, bind 完成修复 2024-08-27 2026-01-06
CVE-2023-31346 Failure to initialize\nmemory in SEV Firmware may allow a privileged attacker to access stale data\nfrom other guests. Moderate linux-firmware 完成修复 2024-08-27 2026-03-18
CVE-2024-6345 A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its d... Important python-setuptools, python39:3.9, fence-agents, python3-setuptools, resource-agents 完成修复 2024-08-26 2026-01-04
CVE-2024-6655 A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK applicati... Important gtk3, gtk2, gtk4 完成修复 2024-08-23 2025-12-30
CVE-2024-6239 A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using... Moderate poppler 完成修复 2024-08-23 2026-07-10
CVE-2024-5629 An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a S... Moderate python-pymongo, python36:3.6 完成修复 2024-08-23 2026-07-10
CVE-2024-37371 In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sen... Moderate krb5, mysql:8.0 完成修复 2024-08-23 2026-06-24
CVE-2024-37370 In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 w... Important krb5 完成修复 2024-08-23 2026-01-09
CVE-2024-2955 T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted c... Moderate wireshark 完成修复 2024-08-23 2026-01-25
CVE-2024-26327 An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest... Moderate qemu 完成修复 2024-08-23 2025-12-18
CVE-2024-2605 An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. Note: T... Important firefox 完成修复 2024-08-23 2025-12-30
CVE-2024-24806 libuv is a multi-platform support library with a focus on asynchronous I/O. The uv_getaddrinfo function in `src/unix/getaddri... Important libuv 完成修复 2024-08-23 2026-01-05
CVE-2024-22201 Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be lea... Important jetty 完成修复 2024-08-23 2026-01-06
CVE-2023-50967 latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Cou... Important jose 完成修复 2024-08-23 2026-01-06
CVE-2023-48161 Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the ... Important java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk, giflib 完成修复 2024-08-23 2025-12-05
CVE-2024-7529 The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting ... Moderate firefox, thunderbird 完成修复 2024-08-22 2026-01-24
CVE-2024-7528 Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < ... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7527 Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, ... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7526 ANGLE failed to initialize parameters which led to reading from uninitialized memory. This could be leveraged to leak sensitive... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7525 It was possible for a web extension with minimal permissions to create a StreamFilter which could be used to read and modify ... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7524 Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site prot... Important firefox 完成修复 2024-08-22 2025-12-30
CVE-2024-7522 Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefo... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7521 Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7520 A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7519 Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an a... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-7518 Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing a... Important firefox, thunderbird 完成修复 2024-08-22 2025-12-30
CVE-2024-34750 Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing ... Important tomcat 完成修复 2024-08-22 2025-12-30
CVE-2023-5841 Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software... Important OpenEXR 完成修复 2024-08-20 2025-12-29
CVE-2024-4603 Issue summary: Checking excessively long DSA keys or parameters may be very \nslow. \nImpact summary: Applications that use the... Moderate openssl 完成修复 2024-08-16 2026-01-05
CVE-2024-4340 Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError. Important python-sqlparse 完成修复 2024-08-16 2026-01-04
CVE-2024-38875 An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential de... Moderate python-django 完成修复 2024-08-16 2026-06-24
CVE-2024-35195 Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests Session, if the first request is made wi... Moderate python27:2.7, python-requests, rust-srpm-macros, python39:3.9 完成修复 2024-08-16 2026-07-10
CVE-2024-34459 An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllin... Moderate libxml2 完成修复 2024-08-16 2026-07-11
CVE-2024-34069 Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker t... Important python-werkzeug 完成修复 2024-08-16 2026-01-04
CVE-2024-33870 An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to a... Moderate ghostscript 完成修复 2024-08-16 2026-01-25
CVE-2024-33869 An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted Po... Moderate ghostscript 完成修复 2024-08-16 2026-01-25
CVE-2024-29040 This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote In... Moderate tpm2-tss 完成修复 2024-08-16 2026-06-26
CVE-2024-1975 If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSS... Important bind9.16, bind 完成修复 2024-08-16 2026-01-06
CVE-2023-52356 A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATile... Important libtiff 完成修复 2024-08-16 2026-01-05
CVE-2023-52355 An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize... Important libtiff 完成修复 2024-08-16 2026-01-05
CVE-2023-3955 A security issue was discovered in Kubernetes where a user \nthat can create pods on Windows nodes may be able to escalate to a... Important kubernetes 完成修复 2024-08-16 2025-12-29
CVE-2022-48622 In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruptio... Important gdk-pixbuf2 完成修复 2024-08-16 2026-01-07
CVE-2024-6104 go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp wr... Moderate grafana, container-tools:2.0, skopeo, container-tools:an8, container-tools:1.0 完成修复 2024-08-14 2026-07-10
CVE-2024-38476 Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script e... Important httpd:2.4, httpd 完成修复 2024-08-14 2026-01-09
CVE-2024-3727 A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated reg... Moderate skopeo, container-tools:an8 完成修复 2024-08-14 2026-07-09
CVE-2024-6237 A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while... Moderate 389-ds-base, 389-ds:1.4 完成修复 2024-08-13 2026-07-13
CVE-2024-40974 In the Linux kernel, the following vulnerability has been resolved:\npowerpc/pseries: Enforce hcall result buffer validity and ... Moderate kernel 完成修复 2024-08-13 2026-01-22
CVE-2024-40927 In the Linux kernel, the following vulnerability has been resolved:\nxhci: Handle TD clearing for multiple streams case\nWhen m... Moderate kernel 完成修复 2024-08-13 2026-01-22
CVE-2024-39502 In the Linux kernel, the following vulnerability has been resolved:\nionic: fix use after netif_napi_del()\nWhen queues are sta... Moderate kernel 完成修复 2024-08-13 2026-01-21
CVE-2024-39487 In the Linux kernel, the following vulnerability has been resolved:\nbonding: Fix out-of-bounds read in bond_option_arp_ip_targ... Moderate kernel 完成修复 2024-08-13 2026-01-21
CVE-2024-39476 In the Linux kernel, the following vulnerability has been resolved:\nmd/raid5: fix deadlock that raid5d() wait for itself to cl... Moderate kernel 完成修复 2024-08-13 2026-01-21

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""