| CVE-2024-24549 |
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/... |
Important |
tomcat |
否 |
完成修复 |
2024-06-06 |
2025-12-30 |
| CVE-2024-24259 |
freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. |
Moderate |
freeglut |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-24258 |
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. |
Moderate |
freeglut |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-23672 |
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocke... |
Important |
tomcat |
否 |
完成修复 |
2024-06-06 |
2025-12-30 |
| CVE-2024-23653 |
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addit... |
Important |
buildkit |
否 |
完成修复 |
2024-06-06 |
2026-01-05 |
| CVE-2024-23652 |
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malici... |
Important |
docker, container-tools:2.0, buildkit, container-tools:1.0 |
否 |
完成修复 |
2024-06-06 |
2026-01-08 |
| CVE-2024-23651 |
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two mali... |
Important |
docker, container-tools:2.0, buildkit, podman, buildah, container-tools:1.0 |
否 |
完成修复 |
2024-06-06 |
2026-01-08 |
| CVE-2024-23284 |
A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, ... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-23280 |
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and ... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-23263 |
A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-23254 |
The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 ... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-23252 |
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority for the following reason: This CVE ID has been reject... |
Moderate |
webkitgtk, webkit2gtk3 |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2024-1135 |
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By craf... |
Important |
python-gunicorn |
否 |
完成修复 |
2024-06-06 |
2026-01-04 |
| CVE-2023-45237 |
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This \nvulnerability can be exploited by an... |
Important |
edk2 |
否 |
完成修复 |
2024-06-06 |
2026-01-08 |
| CVE-2023-45236 |
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This \nvulnerability can be exploited by an... |
Important |
edk2 |
否 |
完成修复 |
2024-06-06 |
2026-01-08 |
| CVE-2023-42956 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sono... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2023-42950 |
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 1... |
Important |
webkitgtk |
否 |
完成修复 |
2024-06-06 |
2025-12-29 |
| CVE-2023-42843 |
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS... |
Moderate |
webkitgtk |
是 |
完成修复 |
2024-06-06 |
2026-07-11 |
| CVE-2023-3966 |
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial... |
Important |
openvswitch |
否 |
完成修复 |
2024-06-06 |
2025-12-29 |
| CVE-2023-37328 |
GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote att... |
Moderate |
gstreamer1-plugins-base |
是 |
完成修复 |
2024-06-06 |
2026-03-18 |
| CVE-2023-26054 |
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affec... |
Moderate |
buildkit |
否 |
完成修复 |
2024-06-06 |
2026-01-22 |
| CVE-2024-36960 |
linux内核中的vmwgfx模块(用于提供VMware虚拟图形硬件的支持)存在越界读漏洞,原因在于vmw_event_f... |
Moderate |
kernel:6.6, kernel |
否 |
完成修复 |
2024-06-05 |
2026-01-23 |
| CVE-2024-24577 |
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to bui... |
Important |
libgit2 |
否 |
完成修复 |
2024-06-05 |
2026-01-04 |
| CVE-2023-6879 |
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1loop... |
Important |
aom |
否 |
完成修复 |
2024-06-05 |
2026-01-06 |
| CVE-2023-45235 |
EDK2's Network Package is susceptible to a buffer overflow vulnerability when \nhandling Server ID option \nfrom a DHCPv6 prox... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2023-45234 |
EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Adver... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2023-45233 |
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options he... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2023-45232 |
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2023-45230 |
EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This \nv... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2022-36765 |
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer ove... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2022-36764 |
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow ... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-08 |
| CVE-2022-36763 |
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow... |
Important |
edk2 |
否 |
完成修复 |
2024-06-05 |
2026-01-07 |
| CVE-2024-3651 |
A flaw was found in the python-idna library. A malicious argument was sent to the idna.encode() function can trigger an uncontr... |
Moderate |
python39:3.9, python-idna |
是 |
完成修复 |
2024-06-04 |
2026-07-13 |
| CVE-2024-33602 |
nscd: netgroup cache assumes NSS callback uses in-buffer strings \nThe Name Service Cache Daemon's (nscd) netgroup cache can co... |
Moderate |
glibc |
是 |
完成修复 |
2024-06-04 |
2025-12-03 |
| CVE-2024-33601 |
nscd: netgroup cache may terminate daemon on memory allocation failure \nThe Name Service Cache Daemon's (nscd) netgroup cache ... |
Moderate |
glibc |
是 |
完成修复 |
2024-06-04 |
2025-12-03 |
| CVE-2024-33600 |
nscd: Null pointer crashes after notfound response \nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found ... |
Moderate |
glibc |
是 |
完成修复 |
2024-06-04 |
2025-12-03 |
| CVE-2024-33599 |
nscd: Stack-based buffer overflow in netgroup cache \nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted ... |
Important |
glibc |
是 |
完成修复 |
2024-06-04 |
2025-12-03 |
| CVE-2024-31083 |
A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when Allocate... |
Important |
xorg-x11-server, tigervnc, xorg-x11-server-Xwayland |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2024-31081 |
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occu... |
Important |
xorg-x11-server, tigervnc, xorg-x11-server-Xwayland |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2024-31080 |
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occu... |
Important |
xorg-x11-server, tigervnc, xorg-x11-server-Xwayland |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2024-28180 |
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker co... |
Moderate |
container-tools:2.0, podman, container-tools:3.0, container-tools:an8, jose, skopeo, grafana |
是 |
完成修复 |
2024-06-04 |
2026-07-13 |
| CVE-2024-27282 |
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is poss... |
Moderate |
ruby, ruby:3.3, ruby:2.5, ruby:3.0 |
是 |
完成修复 |
2024-06-04 |
2026-03-18 |
| CVE-2024-27281 |
An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used... |
Moderate |
ruby, ruby:3.3, ruby:2.5, ruby:3.0 |
是 |
完成修复 |
2024-06-04 |
2026-03-18 |
| CVE-2024-27280 |
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. T... |
Low |
ruby, ruby:3.3, ruby:2.5, ruby:3.0 |
是 |
完成修复 |
2024-06-04 |
2026-03-18 |
| CVE-2024-24786 |
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can... |
Moderate |
skopeo, container-tools:an8 |
是 |
完成修复 |
2024-06-04 |
2026-06-26 |
| CVE-2024-24785 |
If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escapin... |
Moderate |
golang, golang-dbus, go-toolset:an8 |
是 |
完成修复 |
2024-06-04 |
2025-12-11 |
| CVE-2024-24784 |
The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misa... |
Moderate |
golang, golang-dbus, container-tools:an8, go-toolset:an8 |
是 |
完成修复 |
2024-06-04 |
2025-12-11 |
| CVE-2024-24783 |
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify t... |
Moderate |
golang, git-lfs, container-tools:2.0, golang-dbus, container-tools:an8, container-tools:3.0, go-toolset:an8, grafana |
是 |
完成修复 |
2024-06-04 |
2025-12-11 |
| CVE-2024-23650 |
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malici... |
Moderate |
container-tools:2.0, buildkit, buildah, container-tools:an8, podman, container-tools:1.0 |
是 |
完成修复 |
2024-06-04 |
2026-07-13 |
| CVE-2024-23213 |
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2024-23206 |
An access issue was addressed with improved access restrictions. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and i... |
Moderate |
webkitgtk, webkit2gtk3 |
是 |
完成修复 |
2024-06-04 |
2026-07-11 |
| CVE-2024-1313 |
It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapsho... |
Moderate |
grafana, grafana-pcp |
是 |
完成修复 |
2024-06-04 |
2026-07-10 |
| CVE-2023-6597 |
An issue was found in the CPython tempfile.TemporaryDirectory class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3... |
Important |
python39:3.9, python3 |
否 |
完成修复 |
2024-06-04 |
2026-01-09 |
| CVE-2023-45290 |
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.... |
Moderate |
golang, git-lfs, container-tools:2.0, golang-dbus, container-tools:an8, container-tools:3.0, container-tools:4.0, container-tools:1.0, skopeo, go-toolset:an8, grafana |
是 |
完成修复 |
2024-06-04 |
2025-12-11 |
| CVE-2023-45289 |
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client... |
Moderate |
golang, git-lfs, golang-dbus, go-toolset:an8, grafana |
是 |
完成修复 |
2024-06-04 |
2025-12-11 |
| CVE-2023-42890 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2023-42883 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPad... |
Moderate |
webkit2gtk3 |
是 |
完成修复 |
2024-06-04 |
2026-07-12 |
| CVE-2023-42852 |
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2023-32359 |
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2.... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2014-1745 |
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote a... |
Important |
webkit2gtk3 |
否 |
完成修复 |
2024-06-04 |
2026-01-04 |
| CVE-2023-40414 |
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, ... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2024-06-03 |
2026-01-04 |
| CVE-2023-45288 |
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATIO... |
Important |
golang, git-lfs, go-toolset:an8 |
是 |
完成修复 |
2024-05-30 |
2025-12-10 |
| CVE-2024-1312 |
A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time w... |
Moderate |
kernel |
是 |
完成修复 |
2024-05-28 |
2026-01-25 |
| CVE-2024-32002 |
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories wi... |
Important |
git |
否 |
完成修复 |
2024-05-22 |
2026-01-06 |
| CVE-2023-36632 |
DISPUTED The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: ... |
Low |
python3.11, python3 |
是 |
完成修复 |
2024-05-22 |
2026-03-18 |
| CVE-2024-28182 |
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 kee... |
Moderate |
nghttp2, nodejs:18 |
是 |
完成修复 |
2024-05-21 |
2026-06-24 |
| CVE-2024-27983 |
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a... |
Important |
nodejs, nodejs:18 |
否 |
完成修复 |
2024-05-21 |
2026-01-06 |
| CVE-2024-27982 |
The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers... |
Moderate |
nodejs, nodejs:18 |
是 |
完成修复 |
2024-05-21 |
2026-03-18 |
| CVE-2024-25629 |
c-ares is a C library for asynchronous DNS requests. ares__read_line() is used to parse local configuration files such as `/e... |
Moderate |
c-ares, nodejs, nodejs:18 |
是 |
完成修复 |
2024-05-21 |
2026-03-18 |
| CVE-2024-22025 |
A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when ... |
Moderate |
nodejs, nodejs:18 |
是 |
完成修复 |
2024-05-21 |
2026-03-18 |
| CVE-2024-4778 |
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with eno... |
Important |
firefox |
否 |
完成修复 |
2024-05-15 |
2025-12-30 |
| CVE-2024-4764 |
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects ... |
Important |
firefox |
否 |
完成修复 |
2024-05-15 |
2025-12-30 |
| CVE-2024-28085 |
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users... |
Important |
util-linux |
否 |
完成修复 |
2024-05-13 |
2026-01-06 |
| CVE-2024-26602 |
In the Linux kernel, the following vulnerability has been resolved:\nsched/membarrier: reduce the ability to hammer on sys_memb... |
Moderate |
kernel |
否 |
完成修复 |
2024-04-30 |
2026-01-23 |
| CVE-2024-24856 |
The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a\nsuccessful allocation, but the subsequent code direct... |
Moderate |
kernel, kernel:6.6 |
是 |
完成修复 |
2024-04-29 |
2026-01-25 |
| CVE-2024-3302 |
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an ... |
Low |
thunderbird, firefox |
否 |
完成修复 |
2024-04-25 |
2026-01-24 |
| CVE-2024-2961 |
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes ... |
Moderate |
glibc |
否 |
完成修复 |
2024-04-25 |
2025-12-03 |
| CVE-2021-33631 |
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.T... |
Important |
kernel:5.10, kernel:4.19, kernel |
是 |
完成修复 |
2024-04-25 |
2025-12-09 |
| CVE-2024-3864 |
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corrupti... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2025-12-30 |
| CVE-2024-3861 |
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later us... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2026-01-24 |
| CVE-2024-3859 |
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malf... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2026-01-24 |
| CVE-2024-3857 |
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage coll... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2025-12-30 |
| CVE-2024-3854 |
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnera... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2025-12-30 |
| CVE-2024-3852 |
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefo... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2025-12-30 |
| CVE-2024-28835 |
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .p... |
Moderate |
gnutls |
是 |
完成修复 |
2024-04-19 |
2026-03-18 |
| CVE-2024-2609 |
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by ma... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2024-04-19 |
2026-01-24 |
| CVE-2024-21094 |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... |
Moderate |
java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk |
否 |
完成修复 |
2024-04-19 |
2025-12-05 |
| CVE-2024-21085 |
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Sup... |
Moderate |
java-11-openjdk, java-1.8.0-openjdk |
否 |
完成修复 |
2024-04-19 |
2025-12-05 |
| CVE-2024-21068 |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... |
Moderate |
java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk |
否 |
完成修复 |
2024-04-19 |
2025-12-05 |
| CVE-2024-21012 |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... |
Low |
java-11-openjdk, java-17-openjdk |
否 |
完成修复 |
2024-04-19 |
2025-12-05 |
| CVE-2024-21011 |
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... |
Moderate |
java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk |
否 |
完成修复 |
2024-04-19 |
2025-12-05 |
| CVE-2023-51384 |
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints a... |
Low |
openssh |
否 |
完成修复 |
2024-04-16 |
2026-01-22 |
| CVE-2023-38709 |
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP response... |
Moderate |
httpd:2.4, httpd |
是 |
完成修复 |
2024-04-16 |
2026-07-10 |
| CVE-2024-28834 |
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems... |
Moderate |
gnutls |
是 |
完成修复 |
2024-04-12 |
2026-03-18 |
| CVE-2024-27316 |
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 re... |
Important |
httpd:2.4, httpd |
否 |
完成修复 |
2024-04-12 |
2026-01-09 |
| CVE-2023-6516 |
To keep its cache database efficient, named running as a recursive resolver occasionally attempts to clean up the database. I... |
Important |
bind-dyndb-ldap, bind9.16 |
否 |
完成修复 |
2024-04-12 |
2026-01-06 |
| CVE-2023-5679 |
A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolutio... |
Important |
bind-dyndb-ldap, bind9.16 |
否 |
完成修复 |
2024-04-12 |
2026-01-06 |
| CVE-2023-5517 |
A flaw in query-handling code can cause named to exit prematurely with an assertion failure when: \n \n - `nxdomain-redirect... |
Important |
bind-dyndb-ldap, bind9.16 |
否 |
完成修复 |
2024-04-12 |
2026-01-06 |
| CVE-2023-4408 |
The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause pro... |
Important |
bind-dyndb-ldap, bind9.16, dhcp, bind |
否 |
完成修复 |
2024-04-12 |
2026-01-07 |
| CVE-2024-1488 |
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to mo... |
Important |
unbound |
否 |
完成修复 |
2024-04-11 |
2026-01-06 |