CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-22066 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22065 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22064 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22059 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2023-22032 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2024-02-21 2026-03-18
CVE-2024-21404 A denial of service vulnerability exists in .NET applications with OpenSSL support when parsing X509 certificates. The issue ar... Important dotnet6.0 完成修复 2024-02-20 2025-12-05
CVE-2024-21386 A denial of service vulnerability is present in the .NET applications utilizing SignalR, which a malicious client can exploit. ... Important dotnet6.0 完成修复 2024-02-20 2025-12-05
CVE-2023-42465 Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic... Moderate sudo 完成修复 2024-02-18 2026-01-22
CVE-2023-39326 A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more ... Moderate toolbox, container-tools:4.0, go-toolset, golang-dbus, grafana, go-toolset:an8, podman, container-tools:an8, git-lfs, golang 完成修复 2024-02-16 2025-12-11
CVE-2024-22195 A cross-site scripting (XSS) flaw was found in Jinja2 due to the xmlattr filter allowing keys with spaces, contrary to XML/HTM... Moderate python27:2.7, python-jinja2, fence-agents 完成修复 2024-02-06 2026-07-10
CVE-2024-0409 A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. I... Important xorg-x11-server-Xwayland, xorg-x11-server 完成修复 2024-02-06 2026-01-04
CVE-2024-0408 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unl... Moderate xorg-x11-server-Xwayland, xorg-x11-server 完成修复 2024-02-06 2026-07-13
CVE-2023-6246 glibc的syslog函数存在堆溢出漏洞,该漏洞可导致本地提权,影响范围包括:2.36<=版本<2.39,包含我... Important glibc 完成修复 2024-02-06 2025-12-03
CVE-2023-6228 An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a... Moderate libtiff 完成修复 2024-02-06 2026-07-11
CVE-2023-6129 A flaw was found in in the POLY1305 MAC (message authentication code) implementation in OpenSSL, affecting applications running... Moderate mariadb:10.3, mysql, mysql:8.0, openssl, mariadb:10.5, mariadb 完成修复 2024-02-06 2026-01-05
CVE-2023-51764 A flaw was found in some SMTP server configurations in Postfix. This flaw allows a remote attacker to break out email message d... Moderate postfix 完成修复 2024-02-06 2026-07-10
CVE-2023-51714 An integer overflow vulnerability was found in Qt. An incorrect HPack integer overflow check can lead to denial of service. Important qt5-qtbase 完成修复 2024-02-06 2025-12-30
CVE-2023-45139 A flaw was found in the subsetting module of FontTools, which contains an XML External Entity Injection (XXE) vulnerability. Th... Important fonttools 完成修复 2024-02-06 2026-01-07
CVE-2023-41419 An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer... Important python-gevent 完成修复 2024-02-06 2026-01-04
CVE-2023-41056 A flaw was found in Redis. When processing a certain sequence of payloads, Redis may incorrectly handle the resizing of memory ... Important redis, redis:6 完成修复 2024-02-06 2026-01-04
CVE-2022-4065 A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerab... Important testng 完成修复 2024-02-06 2026-01-05
CVE-2021-34429 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to a... Moderate jetty 完成修复 2024-02-06 2026-07-09
CVE-2024-21626 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier,... Important container-tools:4.0, buildah, runc, podman, container-tools:an8, docker 完成修复 2024-02-02 2025-12-29
CVE-2024-0567 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. Th... Moderate gnutls 完成修复 2024-02-02 2026-03-18
CVE-2023-49286 Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value ... Important squid:4, squid 完成修复 2024-02-02 2026-01-04
CVE-2023-49285 Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to... Important squid:4, squid 完成修复 2024-02-02 2026-01-04
CVE-2021-3750 A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overl... Important virt:an, qemu 完成修复 2024-02-02 2025-12-09
CVE-2024-23222 A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS So... Important webkitgtk, webkit2gtk3 完成修复 2024-02-01 2026-01-04
CVE-2024-23307 Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows F... Moderate kernel 完成修复 2024-01-31 2026-01-23
CVE-2024-22099 NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow... Moderate kernel 完成修复 2024-01-31 2026-01-23
CVE-2024-21886 A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application ... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-01-31 2025-12-29
CVE-2024-21885 A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array leng... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-01-31 2025-12-29
CVE-2024-0755 Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memo... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0753 In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, ... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0751 A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox E... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0750 A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permis... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0749 A phishing site could have repurposed an about: dialog to show phishing content with an incorrect origin in the address bar. ... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0747 When a parent page loaded a child in an iframe with unsafe-inline, the parent Content Security Policy could have overridden t... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0746 A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122,... Moderate firefox, thunderbird 完成修复 2024-01-31 2026-01-24
CVE-2024-0742 It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an inco... Important firefox, thunderbird 完成修复 2024-01-31 2025-12-30
CVE-2024-0741 An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. Th... Important firefox, thunderbird 完成修复 2024-01-31 2025-12-30
CVE-2024-0553 A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the r... Important gnutls 完成修复 2024-01-31 2026-01-04
CVE-2024-0229 An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync g... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-01-31 2026-01-04
CVE-2023-6816 A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button curr... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2024-01-31 2025-12-29
CVE-2024-22862 Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser... Moderate ffmpeg 完成修复 2024-01-27 2025-12-06
CVE-2024-22860 Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_rea... Moderate ffmpeg 完成修复 2024-01-27 2025-12-06
CVE-2024-20952 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Important java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20945 It was discovered that the DOMRSAPSSSignatureMethod and DOMSignatureMethod classes in the Security component of OpenJDK could l... Moderate java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20932 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Important java-17-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20926 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Moderate java-11-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20921 A flaw was found in the loop optimizations performed by the Hotspot component of OpenJDK when generating range check predicates... Moderate java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20919 A flaw was found in the way the Hotspot JVM class file verifier verified the correctness of bytecode in the loaded class files.... Moderate java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2024-20918 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (compo... Important java-11-openjdk, java-17-openjdk, java-1.8.0-openjdk 完成修复 2024-01-18 2025-12-05
CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong porti... Moderate python3.10, python3.11, python3, python39:3.9, python 完成修复 2024-01-16 2026-07-10
CVE-2024-0443 A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leak... Moderate kernel 完成修复 2024-01-15 2026-01-23
CVE-2024-21319 Microsoft Identity Denial of service vulnerability Moderate dotnet6.0, dotnet 完成修复 2024-01-11 2025-12-05
CVE-2024-0057 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability Important dotnet6.0, dotnet 完成修复 2024-01-11 2025-12-05
CVE-2024-0056 Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability Important dotnet6.0, dotnet 完成修复 2024-01-11 2025-12-05
CVE-2023-5633 The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the wa... Important kernel 完成修复 2024-01-11 2025-12-09
CVE-2023-5455 Moderate krb5, ipa, idm:DL1 完成修复 2024-01-11 2026-03-18
CVE-2023-4622 A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. ... Important kernel 完成修复 2024-01-10 2025-12-09
CVE-2023-6867 The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on p... Moderate firefox 完成修复 2024-01-05 2026-01-24
CVE-2023-6865 EncryptingOutputStream was susceptible to exposing uninitialized data. This issue could only be abused in order to write data... Important firefox 完成修复 2024-01-05 2025-12-30
CVE-2023-6864 Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-6863 The ShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a ... Moderate firefox, thunderbird 完成修复 2024-01-05 2026-01-24
CVE-2023-6862 A use-after-free was identified in the nsDNSService::Init. This issue appears to manifest rarely during start-up. This vulner... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-6861 The nsWindow::PickerOpen(void) method was susceptible to a heap buffer overflow when running in headless mode. This vulnerabi... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-6860 The VideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the s... Moderate firefox, thunderbird 完成修复 2024-01-05 2026-01-24
CVE-2023-6859 A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 11... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-6858 Firefox was susceptible to a heap buffer overflow in nsTextFragment due to insufficient OOM handling. This vulnerability affe... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-6857 When resolving a symlink, a race may occur where the buffer passed to readlink may actually be smaller than necessary. *This ... Moderate firefox, thunderbird 完成修复 2024-01-05 2026-01-24
CVE-2023-6856 The WebGL DrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver... Important firefox, thunderbird 完成修复 2024-01-05 2025-12-30
CVE-2023-50762 When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the ... Important thunderbird 完成修复 2024-01-05 2026-01-04
CVE-2023-50761 The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If presen... Important thunderbird 完成修复 2024-01-03 2026-01-04
CVE-2023-7104 A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionRea... Moderate sqlite 完成修复 2023-12-29 2026-06-24
CVE-2023-5981 A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response ti... Moderate gnutls 完成修复 2023-12-26 2026-07-13
CVE-2023-1192 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data ... Moderate kernel:4.19, kernel:4.18, kernel, kernel:6.6, kernel:5.10 完成修复 2023-12-25 2026-01-23
CVE-2023-50254 Deepin Linux's default document reader deepin-reader software suffers from a serious vulnerability in versions prior to 6.0.7... Important deepin-reader 完成修复 2023-12-23 2026-01-08
CVE-2023-48795 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attac... Moderate python-pynacl 完成修复 2023-12-21 2026-06-24
CVE-2023-6931 Linuxkernel的Perf组件存在越界写漏洞,在我们的系统里/proc/sys/kernel/perf_event_paranoid为2,禁止普通用... Moderate kernel 完成修复 2023-12-19 2026-01-23
CVE-2023-6932 linuxkernel的igmp组件存在条件竞争导致的uaf漏洞,影响版版本2.6.12-rc2<=版本<6.7-rc4,包含4.19和5.10 Moderate kernel 完成修复 2023-12-18 2026-01-23
CVE-2023-51385 In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this n... Moderate openssh 完成修复 2023-12-18 2026-01-22
CVE-2023-49083 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7... Important python-cryptography, python3.11-cryptography 完成修复 2023-12-14 2026-01-09
CVE-2023-46219 When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests usi... Moderate curl 完成修复 2023-12-14 2026-01-05
CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is ... Moderate curl 完成修复 2023-12-14 2026-01-05
CVE-2023-6277 An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause ... Important libtiff 完成修复 2023-12-13 2026-01-05
CVE-2023-6174 SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file Moderate wireshark 完成修复 2023-12-13 2026-01-22
CVE-2023-48706 Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a :s command fo... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48237 Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a v... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48236 Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values larger t... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48235 Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an overflow. I... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48234 Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large c... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48233 Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signed) long... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48232 Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overl... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-48231 Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Ex... Moderate vim 完成修复 2023-12-13 2026-06-26
CVE-2023-46446 An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the remote end of an SSH client session via packet injecti... Important python-asyncssh 完成修复 2023-12-13 2026-01-04
CVE-2023-45866 Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted co... Important bluez 完成修复 2023-12-08 2026-01-06
CVE-2020-21535 fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c. Moderate transfig 完成修复 2023-12-04 2026-06-26
CVE-2020-21532 fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c. Moderate transfig 完成修复 2023-12-04 2026-06-26
CVE-2023-37732 Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to ca... Moderate yasm 完成修复 2023-11-29 2026-07-13

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""