CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2024-30156 Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows cre... Important varnish, varnish:6 完成修复 2024-04-09 2025-12-30
CVE-2024-22017 setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). \nThis allows the pro... Important nodejs, nodejs:20 完成修复 2024-04-09 2026-01-06
CVE-2024-21896 The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. I... Important nodejs, nodejs:20 完成修复 2024-04-09 2026-01-06
CVE-2024-21891 Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitte... Moderate nodejs, nodejs:20 完成修复 2024-04-09 2026-03-18
CVE-2024-21890 The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of ... Moderate nodejs, nodejs:20 完成修复 2024-04-09 2026-03-18
CVE-2023-6915 linux内核的ida_free存在空指针解引用,可引起Dos,我们的4.19也有引入,影响版本4.20-rc1<=版本<6.7-rc... Moderate kernel 完成修复 2024-04-08 2026-01-23
CVE-2023-42917 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, mac... Important webkit2gtk3 完成修复 2024-04-08 2026-01-04
CVE-2024-26665 linux内核的iptunnel_pmtud_build_icmpv6函数中,如果skb不是线性方式组织在一起的,那么csum_partial会导�... Moderate [a8]kernel, kernel, [a7]kernel, kernel:6.6, [a23]kernel 完成修复 2024-04-07 2026-01-22
CVE-2024-0646 An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls... Important kernel 完成修复 2024-04-03 2025-12-09
CVE-2024-0565 An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-comp... Moderate kernel 完成修复 2024-04-03 2026-01-23
CVE-2023-6817 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege... Important kernel 完成修复 2024-04-03 2025-12-09
CVE-2023-6610 An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue co... Important kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2024-04-03 2025-12-09
CVE-2023-6606 An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could a... Important kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2024-04-03 2025-12-09
CVE-2023-6546 A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the ... Important kernel 完成修复 2024-04-03 2025-12-09
CVE-2023-51042 In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-fr... Moderate kernel 完成修复 2024-04-03 2026-01-25
CVE-2023-46813 An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. I... Important kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2024-04-03 2025-12-09
CVE-2022-48624 close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. Moderate less 完成修复 2024-04-03 2026-01-22
CVE-2023-52628 在linux内核中,对于netfilter的扩展头部字段的匹配存在越界漏洞,如果扩展头部的len刚好是4的倍�... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-04-01 2026-01-22
CVE-2024-3094 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. \nThrough a series of complex obfus... Critical xz 完成修复 2024-03-30 2026-01-09
CVE-2023-6780 An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog an... Moderate glibc 完成修复 2024-03-28 2025-12-03
CVE-2023-6779 An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is ca... Important glibc 完成修复 2024-03-28 2025-12-03
CVE-2024-28757 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_Ex... Moderate expat 完成修复 2024-03-27 2026-07-11
CVE-2023-52425 libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case ... Moderate expat, xmlrpc-c 完成修复 2024-03-27 2026-07-11
CVE-2023-45929 S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr(). Moderate slang 完成修复 2024-03-27 2026-03-18
CVE-2023-45927 S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf(). Moderate slang 完成修复 2024-03-27 2026-03-18
CVE-2024-29944 An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the... Critical firefox 完成修复 2024-03-26 2026-01-04
CVE-2024-2616 To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to contin... Important firefox 完成修复 2024-03-26 2025-12-30
CVE-2024-2614 Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2024-03-26 2025-12-30
CVE-2024-2612 If an attacker could find a way to trigger a particular code path in SafeRefPtr, it could have triggered a crash or potential... Moderate firefox, thunderbird 完成修复 2024-03-26 2026-01-24
CVE-2024-2611 A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. Th... Moderate firefox, thunderbird 完成修复 2024-03-26 2026-01-24
CVE-2024-2610 Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content securit... Moderate firefox, thunderbird 完成修复 2024-03-26 2026-01-24
CVE-2024-2608 AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding() and AppendEncodedCharacters() could have experienced integ... Important firefox, thunderbird 完成修复 2024-03-26 2025-12-30
CVE-2024-2607 Return registers were overwritten which could have allowed an attacker to execute arbitrary code. Note: This issue only affec... Important firefox, thunderbird 完成修复 2024-03-26 2025-12-30
CVE-2024-21892 On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is... Important nodejs:18, nodejs 完成修复 2024-03-26 2026-01-05
CVE-2024-1936 The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in ... Important thunderbird 完成修复 2024-03-26 2026-01-04
CVE-2024-0743 An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects F... Important firefox, thunderbird 完成修复 2024-03-26 2025-12-30
CVE-2023-46809 A flaw was found in Node.js. The privateDecrypt() API of the crypto library may allow a covert timing side-channel during PKCS#... Moderate nodejs:18, nodejs 完成修复 2024-03-26 2026-03-18
CVE-2024-22019 A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, lead... Important nodejs:18, nodejs, nodejs:16 完成修复 2024-03-21 2026-01-05
CVE-2024-1597 pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default... Important postgresql-jdbc 完成修复 2024-03-21 2026-01-04
CVE-2023-51043 In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocki... Moderate kernel 完成修复 2024-03-21 2026-01-23
CVE-2024-26589 linux内核的bpf模块中,check_flow_keys_access函数没有检查偏移是否越界,可导致越界漏洞,影响版本4... Moderate kernel:4.19, kernel, kernel:5.10 完成修复 2024-03-20 2026-01-22
CVE-2024-25617 Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe ... Important squid:4, squid 完成修复 2024-03-20 2026-01-04
CVE-2024-25111 Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service... Important squid:4, squid 完成修复 2024-03-20 2026-01-04
CVE-2023-6186 Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros w... Important libreoffice 完成修复 2024-03-20 2026-01-05
CVE-2023-6185 Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to e... Important libreoffice 完成修复 2024-03-20 2026-01-05
CVE-2023-50269 Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 th... Important squid:4, squid 完成修复 2024-03-20 2026-01-04
CVE-2024-2615 Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2024-03-19 2025-12-30
CVE-2024-26607 linuxkernel的sii902x模块存在空指针解引用漏洞,影响版本5.0-rc1<=版本<6.8-rc2,包含4.19和5.10 Moderate kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2024-03-16 2026-01-22
CVE-2023-52478 hidpp_connect_event可导致TOCTOU条件竞争漏洞,可触发uaf,影响版本3.19-rc1<=版本<6.6-rc6 Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-03-16 2026-01-22
CVE-2023-52445 linux内核的pvrusb2模块存在uaf漏洞,影响版本2.6.26-rc1<=版本<6.8-rc1,包含4.19和5.10 Low kernel 完成修复 2024-03-16 2026-01-24
CVE-2023-50447 Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerabili... Important python-pillow 完成修复 2024-03-14 2026-01-04
CVE-2023-45539 HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information... Important haproxy 完成修复 2024-03-13 2026-01-05
CVE-2024-0914 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded cip... Moderate opencryptoki 完成修复 2024-03-11 2026-07-10
CVE-2024-23301 Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers ... Moderate rear 完成修复 2024-03-06 2026-07-10
CVE-2024-21803 Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code... Low kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-03-06 2026-01-23
CVE-2023-6478 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger ... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-03-05 2026-01-04
CVE-2023-6377 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result i... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-03-05 2026-01-04
CVE-2024-26597 linux内核的rmnet存在全局变量越界读,影响版本4.17-rc1<=版本<6.8-rc1,包含4.19和5.10 Moderate kernel 完成修复 2024-03-04 2026-01-22
CVE-2024-0607 Linux内核的Netfilter模块存在越界写漏洞,和CVE-2023-35001相似,一样的根因,影响版本4.5-rc1<=版本<6.... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-03-04 2026-01-23
CVE-2023-51779 linux内核的Bluetooth存在uaf漏洞,该漏洞是因为bt_sock_recvmsg中没有加锁,导致释放同时触发bt_sock_ioc... Moderate kernel 完成修复 2024-03-04 2026-01-23
CVE-2023-45287 Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied... Moderate git-lfs, container-tools:4.0, skopeo, container-tools:an8 完成修复 2024-02-28 2026-03-18
CVE-2023-45285 Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module... Moderate golang, go-toolset:an8 完成修复 2024-02-28 2025-12-11
CVE-2023-5992 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This ... Moderate opensc 完成修复 2024-02-27 2026-07-09
CVE-2023-50868 The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers t... Important bind, systemd, bind9.16, dhcp, unbound, dnsmasq, bind-dyndb-ldap 完成修复 2024-02-27 2026-01-07
CVE-2023-50387 Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a ... Important bind, systemd, bind9.16, dhcp, unbound, dnsmasq, bind-dyndb-ldap 完成修复 2024-02-27 2026-01-07
CVE-2024-1553 Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2024-02-23 2025-12-30
CVE-2024-1552 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.Note: This issue ... Low firefox, thunderbird 完成修复 2024-02-23 2026-01-24
CVE-2024-1551 Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Conten... Moderate firefox, thunderbird 完成修复 2024-02-23 2026-01-24
CVE-2024-1550 A malicious website could have used a combination of exiting fullscreen mode and requestPointerLock to cause the user's mouse... Moderate firefox, thunderbird 完成修复 2024-02-23 2026-01-24
CVE-2024-1549 If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially re... Moderate firefox, thunderbird 完成修复 2024-02-23 2026-01-24
CVE-2024-1548 A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user... Moderate firefox, thunderbird 完成修复 2024-02-23 2026-01-24
CVE-2024-1547 Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (... Important firefox, thunderbird 完成修复 2024-02-23 2025-12-30
CVE-2024-1546 When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-o... Important firefox, thunderbird 完成修复 2024-02-23 2025-12-30
CVE-2024-0985 Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL f... Important postgresql:12, postgresql:13, postgresql:10, postgresql:15, postgresql 完成修复 2024-02-23 2026-01-04
CVE-2024-24864 A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer d... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-24861 A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-24860 A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result ... Moderate kernel 完成修复 2024-02-22 2026-01-23
CVE-2024-24859 A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-24858 A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-24857 A race condition was found in the Linux kernel's net/bluetooth device driver in conninfo{min,max}_age_set() function. This ca... Moderate kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-24855 A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result i... Moderate kernel:4.19, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-23196 A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result i... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-22386 A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This ca... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-23
CVE-2024-1086 linuxkernel的Netfilter模块存在double-free漏洞,在攻击者具有网络管理员权限时可以导致提权,影响版... Moderate kernel:4.19, kernel, kernel:5.10 完成修复 2024-02-22 2026-01-22
CVE-2023-52438 linuxkernel的shrinker回调中存在一个可通过条件竞争来触发的use-after-free漏洞,影响版本4.20-rc1<=版本... Moderate kernel 完成修复 2024-02-22 2026-01-22
CVE-2024-20983 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2024-20968 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected a... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22115 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22113 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that a... Low mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22112 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22111 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22110 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22103 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22097 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22092 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22084 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43... Moderate mariadb:10.5, mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22079 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22078 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22070 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22068 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""