CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-45145 Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its ... Low python-redis, redis:6, redis 完成修复 2023-10-18 2026-07-10
CVE-2023-39331 A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vuln... Important nodejs, nodejs:20 完成修复 2023-10-18 2026-01-06
CVE-2023-45803 urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTT... Moderate python-urllib3, container-tools:an8, resource-agents, fence-agents, python3.11-urllib3 完成修复 2023-10-17 2026-07-10
CVE-2023-39332 Various node:fs functions allow specifying paths as either strings or Uint8Array objects. In Node.js environments, the `Buf... Important nodejs, nodejs:20 完成修复 2023-10-17 2026-01-06
CVE-2023-22104 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.32... Moderate mysql, mysql:8.0 完成修复 2023-10-17 2026-03-18
CVE-2023-22095 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). The supported version that is affec... Moderate mysql 完成修复 2023-10-17 2026-03-17
CVE-2023-22028 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2023-10-17 2026-03-17
CVE-2023-22026 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2023-10-17 2026-03-17
CVE-2023-22015 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2023-10-17 2026-03-17
CVE-2023-45898 The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent. Important kernel 完成修复 2023-10-16 2025-12-09
CVE-2023-45150 Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was tryin... Moderate ocaml-calendar 完成修复 2023-10-16 2026-03-17
CVE-2023-40791 extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demon... Moderate kernel 完成修复 2023-10-16 2026-01-23
CVE-2022-32091 MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/saniti... Moderate mariadb, mariadb:10.3, mariadb:10.5 完成修复 2023-10-16 2026-06-24
CVE-2022-32089 MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level. Moderate mariadb, mariadb:10.5 完成修复 2023-10-16 2026-06-24
CVE-2022-32084 MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. Moderate mariadb, mariadb:10.3, mariadb:10.5 完成修复 2023-10-16 2026-06-24
CVE-2022-32082 MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. Moderate mariadb, mariadb:10.5 完成修复 2023-10-16 2026-06-24
CVE-2018-25091 urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect th... Moderate python-urllib3, container-tools:an8 完成修复 2023-10-15 2026-03-17
CVE-2023-45863 An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a race con... Moderate kernel 完成修复 2023-10-14 2026-01-23
CVE-2023-5557 A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code out... Important tracker-miners 完成修复 2023-10-13 2025-12-30
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a l... Moderate zlib 完成修复 2023-10-13 2026-06-26
CVE-2023-43789 A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-o... Moderate libXpm, motif 完成修复 2023-10-12 2026-07-11
CVE-2023-38546 A flaw was found in the Curl package. This flaw allows an attacker to insert cookies into a running program using libcurl if th... Moderate curl 完成修复 2023-10-12 2026-01-22
CVE-2023-38039 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers... Important curl 完成修复 2023-10-12 2026-01-06
CVE-2023-5535 Use After Free in GitHub repository vim/vim prior to v9.0.2010. Important vim 完成修复 2023-10-11 2026-01-05
CVE-2023-5176 Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2023-10-11 2025-12-30
CVE-2023-5171 During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write t... Moderate firefox, thunderbird 完成修复 2023-10-11 2026-01-24
CVE-2023-5169 A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, lead... Moderate firefox, thunderbird 完成修复 2023-10-11 2026-01-24
CVE-2023-4813 A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an... Moderate glibc 完成修复 2023-10-11 2025-12-11
CVE-2023-39325 A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consum... Important golang, grafana, go-toolset:an8 完成修复 2023-10-11 2025-12-11
CVE-2023-38545 This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. \n \nWhen curl is asked to pass along the host... Important curl 完成修复 2023-10-11 2026-01-06
CVE-2023-3600 During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable c... Important firefox, thunderbird 完成修复 2023-10-11 2025-12-30
CVE-2023-45648 Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.... Moderate tomcat 完成修复 2023-10-10 2026-06-26
CVE-2023-43788 A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw al... Moderate libXpm, motif 完成修复 2023-10-10 2026-07-11
CVE-2023-43787 A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local use... Moderate libX11 完成修复 2023-10-10 2026-01-22
CVE-2023-43786 A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to... Moderate libX11 完成修复 2023-10-10 2026-07-11
CVE-2023-43785 A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local... Moderate libX11 完成修复 2023-10-10 2026-01-22
CVE-2023-42795 Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 throu... Moderate tomcat, tomcatjss 完成修复 2023-10-10 2026-06-26
CVE-2023-42794 Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 t... Moderate tomcat 完成修复 2023-10-10 2026-06-26
CVE-2023-42670 A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, cau... Moderate samba 完成修复 2023-10-10 2026-07-09
CVE-2023-42669 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack ... Moderate samba 完成修复 2023-10-10 2026-07-09
CVE-2023-4154 A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to p... Important samba 完成修复 2023-10-10 2026-01-09
CVE-2023-4091 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions w... Moderate samba 完成修复 2023-10-10 2026-07-09
CVE-2023-3961 A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of th... Moderate samba 完成修复 2023-10-10 2026-07-09
CVE-2023-36478 Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.... Important jetty 完成修复 2023-10-10 2026-01-06
CVE-2023-43641 libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bound... Important tracker-miners 完成修复 2023-10-09 2025-12-30
CVE-2023-39192 A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 st... Moderate kernel 完成修复 2023-10-09 2026-01-23
CVE-2023-45322 DISPUTED libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This oc... Moderate libxml2 完成修复 2023-10-06 2026-07-11
CVE-2023-39928 A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abu... Important webkitgtk, webkit2gtk3 完成修复 2023-10-06 2026-01-04
CVE-2023-5441 NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. Important vim 完成修复 2023-10-05 2026-01-05
CVE-2023-4911 linux上的glibc存在溢出漏洞,可导致提权,影响版本2.34<=版本<=2.38,我们的5.10上的glibc受影响 Important glibc, compat-glibc 完成修复 2023-10-05 2025-12-11
CVE-2023-39323 Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compil... Moderate ubi8, golang, go-toolset:an8 完成修复 2023-10-05 2025-12-11
CVE-2023-5371 RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or cra... Moderate wireshark 完成修复 2023-10-04 2026-01-22
CVE-2023-43804 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the Cookie HTTP header special or provide an... Important python27:2.7, python-urllib3, python3.11-urllib3, fence-agents, python39:3.9 完成修复 2023-10-04 2026-01-09
CVE-2023-43665 An inefficient regular expression complexity was found in Django. The text truncator regular expressions exhibit linear backtra... Moderate python-django 完成修复 2023-10-04 2026-06-24
CVE-2023-39191 An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper... Important kernel 完成修复 2023-10-04 2025-12-09
CVE-2023-5345 A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escala... Important kernel 完成修复 2023-10-03 2025-12-09
CVE-2023-5344 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969. Important vim 完成修复 2023-10-02 2026-01-05
CVE-2023-43361 Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of s... Important vorbis-tools 完成修复 2023-10-02 2025-12-29
CVE-2023-32820 In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of se... Important kernel 完成修复 2023-10-02 2025-12-09
CVE-2023-44488 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. Important firefox, thunderbird, libvpx 完成修复 2023-09-30 2026-01-07
CVE-2023-44466 An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, lead... Important kernel 完成修复 2023-09-29 2025-12-09
CVE-2023-39410 When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints an... Important log4j 完成修复 2023-09-29 2026-01-05
CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote atta... Important firefox, thunderbird, libvpx 完成修复 2023-09-28 2026-01-07
CVE-2023-5215 A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit uns... Moderate virt:an, libnbd 完成修复 2023-09-28 2026-03-17
CVE-2023-42756 A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can ... Moderate kernel 完成修复 2023-09-28 2026-01-07
CVE-2023-5197 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege... Moderate kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-09-27 2026-01-22
CVE-2023-5174 If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice,... Moderate firefox, thunderbird 完成修复 2023-09-27 2026-01-24
CVE-2023-5168 A compromised content process could have provided malicious data to FilterNodeD2D1 resulting in an out-of-bounds write, leadi... Important firefox, thunderbird 完成修复 2023-09-27 2025-12-30
CVE-2023-5157 A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a d... Important mariadb:10.5, mariadb 完成修复 2023-09-27 2026-01-04
CVE-2023-42822 xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Sinc... Moderate xrdp 完成修复 2023-09-27 2026-07-10
CVE-2023-41074 The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macO... Important webkitgtk, webkit2gtk3 完成修复 2023-09-27 2026-01-04
CVE-2023-40451 This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScrip... Moderate webkitgtk, webkit2gtk3 完成修复 2023-09-27 2026-03-17
CVE-2023-39434 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, ... Moderate webkitgtk, webkit2gtk3 完成修复 2023-09-27 2026-03-17
CVE-2023-35074 The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS... Important webkitgtk, webkit2gtk3 完成修复 2023-09-27 2026-01-04
CVE-2023-5158 A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This i... Moderate kernel 完成修复 2023-09-25 2026-01-07
CVE-2023-5156 A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may res... Important glibc 完成修复 2023-09-25 2025-12-03
CVE-2023-5129 This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863. Important firefox, libwebp, thunderbird 完成修复 2023-09-25 2026-01-07
CVE-2023-43642 snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was fou... Moderate log4j 完成修复 2023-09-25 2026-07-10
CVE-2023-42755 A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyon... Moderate kernel 完成修复 2023-09-25 2026-01-07
CVE-2023-42753 An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a misca... Moderate kernel 完成修复 2023-09-25 2026-01-07
CVE-2023-4156 A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to ... Important gawk 完成修复 2023-09-25 2026-01-04
CVE-2023-34319 The fix for XSA-423 added logic to Linux'es netback driver to deal with \na frontend splitting a packet in a way such that not ... Moderate kernel 完成修复 2023-09-22 2026-01-07
CVE-2023-22044 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (compo... Low java-17-openjdk 完成修复 2023-09-22 2025-12-05
CVE-2023-5115 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious ... Moderate ansible-core 完成修复 2023-09-21 2026-03-17
CVE-2023-4504 Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptibl... Important cups 完成修复 2023-09-21 2026-01-04
CVE-2023-43090 A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the... Moderate gnome-shell 完成修复 2023-09-21 2026-07-13
CVE-2023-42456 Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, b... Important sudo, sudo-rs 完成修复 2023-09-21 2026-01-08
CVE-2023-41993 The issue was addressed with improved checks. This issue is fixed in Safari 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14. Proc... Moderate webkitgtk, webkit2gtk3 完成修复 2023-09-21 2026-07-11
CVE-2023-4863 Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds mem... Important firefox, libwebp, thunderbird 完成修复 2023-09-20 2026-01-07
CVE-2023-4236 A flaw in the networking code handling DNS-over-TLS queries may cause named to terminate unexpectedly due to an assertion fai... Important bind 完成修复 2023-09-20 2026-01-06
CVE-2023-38802 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP ... Important frr 完成修复 2023-09-20 2026-01-07
CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current num... Important virt:an, qemu-kvm 完成修复 2023-09-20 2025-12-09
CVE-2023-3341 The code that processes control channel messages sent to named calls certain functions recursively during packet parsing. Rec... Important bind9.16, bind, bind-dyndb-ldap 完成修复 2023-09-20 2026-01-04
CVE-2023-22024 In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_R... Moderate kernel 完成修复 2023-09-20 2026-01-23
CVE-2023-2163 Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe \ncode paths being incorrectly marked as safe, resul... Important kernel 完成修复 2023-09-20 2025-12-09
CVE-2019-19450 paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted u... Important python-reportlab 完成修复 2023-09-20 2026-01-04
CVE-2023-4806 A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resu... Moderate glibc 完成修复 2023-09-18 2025-12-03
CVE-2023-4527 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configur... Moderate glibc 完成修复 2023-09-18 2025-12-03
CVE-2023-43115 In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript document... Important ghostscript 完成修复 2023-09-18 2026-01-06
CVE-2020-36766 An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on s... Low kernel 完成修复 2023-09-18 2026-01-22

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""