CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2024-24549 Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/... Important tomcat 完成修复 2024-06-06 2025-12-30
CVE-2024-24259 freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. Moderate freeglut 完成修复 2024-06-06 2026-07-11
CVE-2024-24258 freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. Moderate freeglut 完成修复 2024-06-06 2026-07-11
CVE-2024-23672 Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocke... Important tomcat 完成修复 2024-06-06 2025-12-30
CVE-2024-23653 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addit... Important buildkit 完成修复 2024-06-06 2026-01-05
CVE-2024-23652 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malici... Important docker, container-tools:2.0, buildkit, container-tools:1.0 完成修复 2024-06-06 2026-01-08
CVE-2024-23651 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two mali... Important docker, container-tools:2.0, buildkit, podman, buildah, container-tools:1.0 完成修复 2024-06-06 2026-01-08
CVE-2024-23284 A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, ... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2024-23280 An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and ... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2024-23263 A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2024-23254 The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 ... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2024-23252 This CVE ID has been rejected or withdrawn by its CVE Numbering Authority for the following reason: This CVE ID has been reject... Moderate webkitgtk, webkit2gtk3 完成修复 2024-06-06 2026-07-11
CVE-2024-1135 Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By craf... Important python-gunicorn 完成修复 2024-06-06 2026-01-04
CVE-2023-45237 EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This \nvulnerability can be exploited by an... Important edk2 完成修复 2024-06-06 2026-01-08
CVE-2023-45236 EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This \nvulnerability can be exploited by an... Important edk2 完成修复 2024-06-06 2026-01-08
CVE-2023-42956 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sono... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2023-42950 A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 1... Important webkitgtk 完成修复 2024-06-06 2025-12-29
CVE-2023-42843 An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS... Moderate webkitgtk 完成修复 2024-06-06 2026-07-11
CVE-2023-3966 A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial... Important openvswitch 完成修复 2024-06-06 2025-12-29
CVE-2023-37328 GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote att... Moderate gstreamer1-plugins-base 完成修复 2024-06-06 2026-03-18
CVE-2023-26054 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affec... Moderate buildkit 完成修复 2024-06-06 2026-01-22
CVE-2024-36960 linux内核中的vmwgfx模块(用于提供VMware虚拟图形硬件的支持)存在越界读漏洞,原因在于vmw_event_f... Moderate kernel:6.6, kernel 完成修复 2024-06-05 2026-01-23
CVE-2024-24577 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to bui... Important libgit2 完成修复 2024-06-05 2026-01-04
CVE-2023-6879 Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1loop... Important aom 完成修复 2024-06-05 2026-01-06
CVE-2023-45235 EDK2's Network Package is susceptible to a buffer overflow vulnerability when \nhandling Server ID option \nfrom a DHCPv6 prox... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2023-45234 EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Adver... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2023-45233 EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options he... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2023-45232 EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2023-45230 EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This \nv... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2022-36765 EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer ove... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2022-36764 EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow ... Important edk2 完成修复 2024-06-05 2026-01-08
CVE-2022-36763 EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow... Important edk2 完成修复 2024-06-05 2026-01-07
CVE-2024-3651 A flaw was found in the python-idna library. A malicious argument was sent to the idna.encode() function can trigger an uncontr... Moderate python39:3.9, python-idna 完成修复 2024-06-04 2026-07-13
CVE-2024-33602 nscd: netgroup cache assumes NSS callback uses in-buffer strings \nThe Name Service Cache Daemon's (nscd) netgroup cache can co... Moderate glibc 完成修复 2024-06-04 2025-12-03
CVE-2024-33601 nscd: netgroup cache may terminate daemon on memory allocation failure \nThe Name Service Cache Daemon's (nscd) netgroup cache ... Moderate glibc 完成修复 2024-06-04 2025-12-03
CVE-2024-33600 nscd: Null pointer crashes after notfound response \nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found ... Moderate glibc 完成修复 2024-06-04 2025-12-03
CVE-2024-33599 nscd: Stack-based buffer overflow in netgroup cache \nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted ... Important glibc 完成修复 2024-06-04 2025-12-03
CVE-2024-31083 A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when Allocate... Important xorg-x11-server, tigervnc, xorg-x11-server-Xwayland 完成修复 2024-06-04 2026-01-04
CVE-2024-31081 A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occu... Important xorg-x11-server, tigervnc, xorg-x11-server-Xwayland 完成修复 2024-06-04 2026-01-04
CVE-2024-31080 A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occu... Important xorg-x11-server, tigervnc, xorg-x11-server-Xwayland 完成修复 2024-06-04 2026-01-04
CVE-2024-28180 Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker co... Moderate container-tools:2.0, podman, container-tools:3.0, container-tools:an8, jose, skopeo, grafana 完成修复 2024-06-04 2026-07-13
CVE-2024-27282 An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is poss... Moderate ruby, ruby:3.3, ruby:2.5, ruby:3.0 完成修复 2024-06-04 2026-03-18
CVE-2024-27281 An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used... Moderate ruby, ruby:3.3, ruby:2.5, ruby:3.0 完成修复 2024-06-04 2026-03-18
CVE-2024-27280 A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. T... Low ruby, ruby:3.3, ruby:2.5, ruby:3.0 完成修复 2024-06-04 2026-03-18
CVE-2024-24786 The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can... Moderate skopeo, container-tools:an8 完成修复 2024-06-04 2026-06-26
CVE-2024-24785 If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escapin... Moderate golang, golang-dbus, go-toolset:an8 完成修复 2024-06-04 2025-12-11
CVE-2024-24784 The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misa... Moderate golang, golang-dbus, container-tools:an8, go-toolset:an8 完成修复 2024-06-04 2025-12-11
CVE-2024-24783 Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify t... Moderate golang, git-lfs, container-tools:2.0, golang-dbus, container-tools:an8, container-tools:3.0, go-toolset:an8, grafana 完成修复 2024-06-04 2025-12-11
CVE-2024-23650 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malici... Moderate container-tools:2.0, buildkit, buildah, container-tools:an8, podman, container-tools:1.0 完成修复 2024-06-04 2026-07-13
CVE-2024-23213 The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3... Important webkitgtk, webkit2gtk3 完成修复 2024-06-04 2026-01-04
CVE-2024-23206 An access issue was addressed with improved access restrictions. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and i... Moderate webkitgtk, webkit2gtk3 完成修复 2024-06-04 2026-07-11
CVE-2024-1313 It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapsho... Moderate grafana, grafana-pcp 完成修复 2024-06-04 2026-07-10
CVE-2023-6597 An issue was found in the CPython tempfile.TemporaryDirectory class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3... Important python39:3.9, python3 完成修复 2024-06-04 2026-01-09
CVE-2023-45290 When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.... Moderate golang, git-lfs, container-tools:2.0, golang-dbus, container-tools:an8, container-tools:3.0, container-tools:4.0, container-tools:1.0, skopeo, go-toolset:an8, grafana 完成修复 2024-06-04 2025-12-11
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client... Moderate golang, git-lfs, golang-dbus, go-toolset:an8, grafana 完成修复 2024-06-04 2025-12-11
CVE-2023-42890 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS... Important webkitgtk, webkit2gtk3 完成修复 2024-06-04 2026-01-04
CVE-2023-42883 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPad... Moderate webkit2gtk3 完成修复 2024-06-04 2026-07-12
CVE-2023-42852 A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and... Important webkit2gtk3 完成修复 2024-06-04 2026-01-04
CVE-2023-32359 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2.... Important webkit2gtk3 完成修复 2024-06-04 2026-01-04
CVE-2014-1745 Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote a... Important webkit2gtk3 完成修复 2024-06-04 2026-01-04
CVE-2023-40414 A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, ... Important webkitgtk, webkit2gtk3 完成修复 2024-06-03 2026-01-04
CVE-2023-45288 An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATIO... Important golang, git-lfs, go-toolset:an8 完成修复 2024-05-30 2025-12-10
CVE-2024-1312 A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time w... Moderate kernel 完成修复 2024-05-28 2026-01-25
CVE-2024-32002 Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories wi... Important git 完成修复 2024-05-22 2026-01-06
CVE-2023-36632 DISPUTED The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: ... Low python3.11, python3 完成修复 2024-05-22 2026-03-18
CVE-2024-28182 nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 kee... Moderate nghttp2, nodejs:18 完成修复 2024-05-21 2026-06-24
CVE-2024-27983 An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a... Important nodejs, nodejs:18 完成修复 2024-05-21 2026-01-06
CVE-2024-27982 The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers... Moderate nodejs, nodejs:18 完成修复 2024-05-21 2026-03-18
CVE-2024-25629 c-ares is a C library for asynchronous DNS requests. ares__read_line() is used to parse local configuration files such as `/e... Moderate c-ares, nodejs, nodejs:18 完成修复 2024-05-21 2026-03-18
CVE-2024-22025 A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when ... Moderate nodejs, nodejs:18 完成修复 2024-05-21 2026-03-18
CVE-2024-4778 Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-05-15 2025-12-30
CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects ... Important firefox 完成修复 2024-05-15 2025-12-30
CVE-2024-28085 wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users... Important util-linux 完成修复 2024-05-13 2026-01-06
CVE-2024-26602 In the Linux kernel, the following vulnerability has been resolved:\nsched/membarrier: reduce the ability to hammer on sys_memb... Moderate kernel 完成修复 2024-04-30 2026-01-23
CVE-2024-24856 The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a\nsuccessful allocation, but the subsequent code direct... Moderate kernel, kernel:6.6 完成修复 2024-04-29 2026-01-25
CVE-2024-3302 There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an ... Low thunderbird, firefox 完成修复 2024-04-25 2026-01-24
CVE-2024-2961 The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes ... Moderate glibc 完成修复 2024-04-25 2025-12-03
CVE-2021-33631 Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.T... Important kernel:5.10, kernel:4.19, kernel 完成修复 2024-04-25 2025-12-09
CVE-2024-3864 Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corrupti... Important firefox, thunderbird 完成修复 2024-04-19 2025-12-30
CVE-2024-3861 If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later us... Moderate firefox, thunderbird 完成修复 2024-04-19 2026-01-24
CVE-2024-3859 On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malf... Moderate firefox, thunderbird 完成修复 2024-04-19 2026-01-24
CVE-2024-3857 The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage coll... Important firefox, thunderbird 完成修复 2024-04-19 2025-12-30
CVE-2024-3854 In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnera... Important firefox, thunderbird 完成修复 2024-04-19 2025-12-30
CVE-2024-3852 GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefo... Important firefox, thunderbird 完成修复 2024-04-19 2025-12-30
CVE-2024-28835 A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .p... Moderate gnutls 完成修复 2024-04-19 2026-03-18
CVE-2024-2609 The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by ma... Moderate firefox, thunderbird 完成修复 2024-04-19 2026-01-24
CVE-2024-21094 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Moderate java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk 完成修复 2024-04-19 2025-12-05
CVE-2024-21085 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Sup... Moderate java-11-openjdk, java-1.8.0-openjdk 完成修复 2024-04-19 2025-12-05
CVE-2024-21068 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Moderate java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk 完成修复 2024-04-19 2025-12-05
CVE-2024-21012 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Low java-11-openjdk, java-17-openjdk 完成修复 2024-04-19 2025-12-05
CVE-2024-21011 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Moderate java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk 完成修复 2024-04-19 2025-12-05
CVE-2023-51384 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints a... Low openssh 完成修复 2024-04-16 2026-01-22
CVE-2023-38709 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP response... Moderate httpd:2.4, httpd 完成修复 2024-04-16 2026-07-10
CVE-2024-28834 A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems... Moderate gnutls 完成修复 2024-04-12 2026-03-18
CVE-2024-27316 HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 re... Important httpd:2.4, httpd 完成修复 2024-04-12 2026-01-09
CVE-2023-6516 To keep its cache database efficient, named running as a recursive resolver occasionally attempts to clean up the database. I... Important bind-dyndb-ldap, bind9.16 完成修复 2024-04-12 2026-01-06
CVE-2023-5679 A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolutio... Important bind-dyndb-ldap, bind9.16 完成修复 2024-04-12 2026-01-06
CVE-2023-5517 A flaw in query-handling code can cause named to exit prematurely with an assertion failure when: \n \n - `nxdomain-redirect... Important bind-dyndb-ldap, bind9.16 完成修复 2024-04-12 2026-01-06
CVE-2023-4408 The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause pro... Important bind-dyndb-ldap, bind9.16, dhcp, bind 完成修复 2024-04-12 2026-01-07
CVE-2024-1488 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to mo... Important unbound 完成修复 2024-04-11 2026-01-06

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""