CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-46589 Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.... Important tomcat, pki-servlet-engine 完成修复 2023-11-28 2025-12-30
CVE-2023-47038 A vulnerability was found in perl. This issue occurs when a crafted regular expression is compiled by perl, which can allow an ... Important perl, perl:5.32 完成修复 2023-11-25 2025-12-29
CVE-2023-5972 A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could a... Moderate kernel 完成修复 2023-11-23 2026-01-23
CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memo... Important thunderbird, firefox 完成修复 2023-11-21 2026-01-04
CVE-2023-6209 Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used t... Moderate thunderbird, firefox 完成修复 2023-11-21 2026-01-24
CVE-2023-6208 When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporar... Moderate thunderbird, firefox 完成修复 2023-11-21 2026-01-24
CVE-2023-6207 Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < ... Important thunderbird, firefox 完成修复 2023-11-21 2026-01-04
CVE-2023-6206 The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It... Important thunderbird, firefox 完成修复 2023-11-21 2026-01-04
CVE-2023-6205 It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an explo... Important thunderbird, firefox 完成修复 2023-11-21 2026-01-04
CVE-2023-6204 On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memo... Important thunderbird, firefox 完成修复 2023-11-21 2026-01-04
CVE-2023-22025 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (comp... Low java-17-openjdk 完成修复 2023-11-17 2025-12-05
CVE-2023-42754 A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated ... Moderate kernel 完成修复 2023-11-16 2026-01-23
CVE-2023-3867 Important kernel:6.6, kernel:5.10, kernel, kernel:4.19 完成修复 2023-11-16 2025-12-09
CVE-2023-6176 linux内核里的加密算法api存在一个空指针解引用漏洞,无法利用,评级低危,影响版本5.7-rc7<=版�... Moderate kernel:5.10, kernel:4.19, kernel 完成修复 2023-11-15 2026-01-23
CVE-2023-6175 A heap-based buffer overflow was found in Wireshark's NetScreen file parser. This issue may allow local arbitrary code executio... Moderate wireshark 完成修复 2023-11-15 2026-01-22
CVE-2023-44444 A parsing vulnerability was found in the GNU Image Manipulation Program (GIMP). This flaw allows an unauthenticated, remote att... Important gimp:2.8, gimp 完成修复 2023-11-14 2026-01-06
CVE-2023-44443 A parsing vulnerability was found in the GNU Image Manipulation Program (GIMP). This flaw allows an unauthenticated, remote att... Important gimp:2.8, gimp 完成修复 2023-11-14 2026-01-06
CVE-2023-44442 A parsing vulnerability was found in the GNU Image Manipulation Program (GIMP). This flaw allows an unauthenticated, remote att... Important gimp:2.8, gimp 完成修复 2023-11-14 2026-01-06
CVE-2023-44441 A parsing vulnerability was found in the GNU Image Manipulation Program (GIMP). This flaw allows an unauthenticated, remote att... Important gimp:2.8, gimp 完成修复 2023-11-14 2026-01-06
CVE-2023-36558 ASP.NET Core - Security Feature Bypass Vulnerability Moderate dotnet6.0, dotnet 完成修复 2023-11-14 2025-12-05
CVE-2023-36049 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability Moderate dotnet6.0, dotnet 完成修复 2023-11-14 2025-12-05
CVE-2023-20592 Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to a... Moderate linux-firmware 完成修复 2023-11-14 2025-12-18
CVE-2023-44446 A use-after-free flaw was found in the MXF demuxer in GStreamer when handling certain MXF video files. This issue could allow a... Important gstreamer-plugins-bad-free, gstreamer1-plugins-bad-free 完成修复 2023-11-13 2026-01-05
CVE-2023-44429 A heap-based buffer overflow vulnerability was found in GStreamer in the AV1 codec parser when handling certain malformed strea... Important gstreamer1-plugins-bad-free 完成修复 2023-11-13 2025-12-29
CVE-2023-44271 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a gi... Important python-pillow 完成修复 2023-11-10 2026-01-04
CVE-2023-5870 The documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can sign... Low postgresql:15, postgresql, postgresql:13, postgresql:12 完成修复 2023-11-09 2026-07-10
CVE-2023-5869 While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a m... Important postgresql:15, postgresql:12, postgresql:13, postgresql, postgresql:10 完成修复 2023-11-09 2026-01-04
CVE-2023-5868 Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "... Moderate postgresql:15, postgresql, postgresql:13, postgresql:12 完成修复 2023-11-09 2026-07-10
CVE-2023-45283 The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Ro... Important golang, perl-File-Path, golang-dbus 完成修复 2023-11-09 2025-12-11
CVE-2023-5090 A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs whe... Moderate kernel 完成修复 2023-11-06 2025-12-18
CVE-2023-46728 Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vuln... Important squid:4, squid 完成修复 2023-11-06 2026-01-04
CVE-2023-4535 An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption... Low opensc 完成修复 2023-11-06 2026-07-10
CVE-2023-44398 Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An ... Moderate exiv2 完成修复 2023-11-06 2026-07-11
CVE-2023-40661 Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pk... Moderate opensc 完成修复 2023-11-06 2026-01-22
CVE-2023-40660 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it ca... Moderate opensc 完成修复 2023-11-06 2026-01-22
CVE-2023-38407 bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing. Moderate frr 完成修复 2023-11-06 2026-07-10
CVE-2023-38406 bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow." Moderate frr 完成修复 2023-11-06 2026-07-10
CVE-2023-5088 A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 inst... Moderate qemu, virt:an 完成修复 2023-11-03 2025-12-18
CVE-2023-47235 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is pr... Moderate frr 完成修复 2023-11-03 2026-07-10
CVE-2023-47234 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a M... Moderate frr 完成修复 2023-11-03 2026-07-10
CVE-2023-1194 An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba serve... Moderate kernel:5.10, kernel:4.19 完成修复 2023-11-03 2026-01-23
CVE-2022-3172 A security issue was discovered in kube-apiserver that allows an \naggregated API server to redirect client traffic to any URL.... Moderate kubernetes 完成修复 2023-11-03 2026-03-18
CVE-2020-28407 In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack ag... Moderate swtpm 完成修复 2023-11-03 2026-01-22
CVE-2023-46724 Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 ... Important squid:4, squid 完成修复 2023-11-01 2026-01-04
CVE-2023-46695 An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on... Low python-django 完成修复 2023-11-01 2026-07-10
CVE-2023-3972 A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling... Important insights-client 完成修复 2023-11-01 2026-01-06
CVE-2023-22081 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: JSSE). Supported versions tha... Moderate java-11-openjdk, java-1.8.0-openjdk, java-17-openjdk 完成修复 2023-11-01 2025-12-05
CVE-2023-22067 Vulnerability in Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381 and 8u381-pe... Moderate java-1.8.0-openjdk 完成修复 2023-11-01 2025-12-05
CVE-2023-5871 A malicious NBD server can easily crash libnbd Refer:\nhttps://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.o... Moderate libnbd 完成修复 2023-10-31 2026-03-18
CVE-2023-5178 linux内核的NVMe-oF/TCP模块中存在uaf漏洞,因为是网络相关的模块触发要求权限低所以评分偏高,影... Important kernel 完成修复 2023-10-31 2025-12-09
CVE-2023-45871 linux的IGB驱动存在越界漏洞,评分高是因为触发要求的权限低且是网络相关的,影响版本3.4rc1<=版... Important kernel 完成修复 2023-10-31 2025-12-09
CVE-2022-3140 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional s... Moderate libreoffice 完成修复 2023-10-31 2026-07-11
CVE-2023-46862 An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_sho... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2023-10-29 2026-01-23
CVE-2023-46853 In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of ... Moderate memcached 完成修复 2023-10-27 2026-01-22
CVE-2023-46852 In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces ... Important memcached 完成修复 2023-10-27 2026-01-04
CVE-2023-46246 Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inn... Moderate vim 完成修复 2023-10-27 2026-06-26
CVE-2023-34059 open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root... Important open-vm-tools 完成修复 2023-10-27 2026-01-05
CVE-2023-34058 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Pr... Important open-vm-tools 完成修复 2023-10-27 2026-01-05
CVE-2023-5731 Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2023-10-26 2025-12-30
CVE-2023-46753 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory at... Moderate frr 完成修复 2023-10-26 2026-07-10
CVE-2023-46752 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash. Moderate frr 完成修复 2023-10-26 2026-07-10
CVE-2023-46234 browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fed... Important firefox 完成修复 2023-10-26 2025-12-30
CVE-2023-45143 Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization he... Low nodejs, nodejs:18, nodejs:20 完成修复 2023-10-26 2026-03-18
CVE-2023-39936 In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 fil... Important graphite2 完成修复 2023-10-26 2026-01-04
CVE-2023-39427 In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper... Important graphite2 完成修复 2023-10-26 2026-01-04
CVE-2023-39333 Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to... Moderate nodejs, nodejs:16, nodejs:18 完成修复 2023-10-26 2026-03-18
CVE-2023-38552 When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept th... Important nodejs, nodejs:18 完成修复 2023-10-26 2026-01-06
CVE-2023-5752 When installing a package from a Mercurial VCS URL (ie "pip install \nhg+...") with pip prior to v23.3, the specified Mercuria... Moderate python-pip 完成修复 2023-10-25 2026-06-24
CVE-2023-5717 A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploite... Moderate kernel 完成修复 2023-10-25 2026-01-22
CVE-2023-5574 A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuratio... Important xorg-x11-server 完成修复 2023-10-25 2026-01-04
CVE-2023-5380 A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration... Moderate xorg-x11-server, tigervnc 完成修复 2023-10-25 2026-07-13
CVE-2023-5367 A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offs... Important xorg-x11-server, tigervnc, xorg-x11-server-Xwayland 完成修复 2023-10-25 2026-01-04
CVE-2023-46316 In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines. Moderate traceroute 完成修复 2023-10-25 2026-06-26
CVE-2023-46233 A vulnerability was found in crypto-js in how PBKDF2 is 1,000 times weaker than originally specified in 1993 and at least 1,300... Important dotnet6.0 完成修复 2023-10-25 2025-12-05
CVE-2023-46136 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed... Important python-werkzeug 完成修复 2023-10-25 2026-01-04
CVE-2023-41983 The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iP... Moderate webkitgtk, webkit2gtk3 完成修复 2023-10-25 2026-07-11
CVE-2023-5732 An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when vi... Moderate firefox, thunderbird 完成修复 2023-10-24 2026-01-24
CVE-2023-5730 Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2023-10-24 2025-12-30
CVE-2023-5728 During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially ... Moderate firefox, thunderbird 完成修复 2023-10-24 2026-01-24
CVE-2023-5727 The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run ... Moderate thunderbird, firefox 完成修复 2023-10-24 2026-01-24
CVE-2023-5726 A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion... Moderate thunderbird, firefox 完成修复 2023-10-24 2026-01-24
CVE-2023-5725 A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect ... Moderate firefox, thunderbird 完成修复 2023-10-24 2026-01-24
CVE-2023-5724 Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vul... Moderate firefox, thunderbird 完成修复 2023-10-24 2026-01-24
CVE-2023-5721 It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insu... Important firefox, thunderbird 完成修复 2023-10-24 2025-12-30
CVE-2023-5678 Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very s... Moderate openssl 完成修复 2023-10-24 2026-01-05
CVE-2023-5363 Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to pote... Moderate shim, openssl, openssl-pkcs11 完成修复 2023-10-24 2026-07-09
CVE-2023-45802 When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not re... Moderate httpd:2.4, httpd 完成修复 2023-10-22 2026-06-24
CVE-2023-43622 An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefi... Important httpd:2.4, httpd 完成修复 2023-10-22 2026-01-09
CVE-2023-31122 Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. Important httpd:2.4, httpd 完成修复 2023-10-22 2026-01-09
CVE-2021-42532 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting ... Important exempi 完成修复 2023-10-20 2026-01-07
CVE-2021-42531 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting ... Important exempi 完成修复 2023-10-20 2026-01-07
CVE-2021-42530 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting ... Important exempi 完成修复 2023-10-20 2026-01-07
CVE-2021-42529 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting ... Important exempi 完成修复 2023-10-20 2026-01-07
CVE-2021-42528 XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file... Moderate exempi 完成修复 2023-10-20 2026-03-18
CVE-2023-5824 Squid is vulnerable to Denial of Service attack against HTTP and HTTPS clients due to an Improper Handling of Structural Elemen... Important squid:4, squid 完成修复 2023-10-19 2026-01-04
CVE-2023-46848 Description: \na) Due to an Incorrect Conversion between Numeric Types \nbug Squid is vulnerable to a Denial of Service \nattac... Important squid:4, squid 完成修复 2023-10-19 2026-01-04
CVE-2023-46847 Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB o... Critical squid:4, squid 完成修复 2023-10-19 2026-01-07
CVE-2023-46846 SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/... Important squid:4, squid 完成修复 2023-10-19 2026-01-04
CVE-2023-34050 In spring AMQP versions 1.0.0 to\n2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class\nnames were added ... Moderate log4j 完成修复 2023-10-19 2026-07-10
CVE-2021-36052 XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary c... Important exempi 完成修复 2023-10-19 2026-01-07

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""