| CVE-2023-41900 |
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to wea... |
Low |
jetty |
是 |
完成修复 |
2023-09-15 |
2026-07-09 |
| CVE-2023-40167 |
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the ... |
Moderate |
jetty |
是 |
完成修复 |
2023-09-15 |
2026-07-09 |
| CVE-2023-36479 |
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very speci... |
Low |
jetty |
是 |
完成修复 |
2023-09-15 |
2026-07-09 |
| CVE-2023-42503 |
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue... |
Moderate |
apache-commons-compress |
否 |
完成修复 |
2023-09-14 |
2025-12-05 |
| CVE-2023-35824 |
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm11... |
Moderate |
kernel |
否 |
完成修复 |
2023-09-14 |
2026-01-07 |
| CVE-2023-35823 |
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/sa... |
Moderate |
kernel |
否 |
完成修复 |
2023-09-14 |
2026-01-07 |
| CVE-2023-4421 |
This patch defeats Bleichenbacher by not trying to hide the size of the\ndecrypted text, but to hide if the text succeeded for ... |
Moderate |
python-nss |
是 |
完成修复 |
2023-09-13 |
2026-06-26 |
| CVE-2023-41081 |
Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such... |
Moderate |
mod_jk, httpd |
是 |
完成修复 |
2023-09-13 |
2026-07-10 |
| CVE-2023-36799 |
.NET Core and Visual Studio Denial of Service Vulnerability |
Moderate |
dotnet6.0 |
否 |
完成修复 |
2023-09-13 |
2025-12-05 |
| CVE-2023-3255 |
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an... |
Moderate |
virt-what, virt:an, qemu-kvm, qemu |
否 |
完成修复 |
2023-09-13 |
2025-12-18 |
| CVE-2023-4921 |
A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege e... |
Moderate |
kernel |
否 |
完成修复 |
2023-09-12 |
2026-01-22 |
| CVE-2023-4582 |
Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-11 |
2026-01-04 |
| CVE-2023-4576 |
On Windows, an integer overflow could occur in RecordedSourceSurfaceCreation which resulted in a heap buffer overflow potenti... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-11 |
2025-12-30 |
| CVE-2023-32558 |
The use of the deprecated API process.binding() can bypass the permission model through path traversal. \n \nThis vulnerabil... |
Important |
nodejs |
否 |
完成修复 |
2023-09-11 |
2026-01-06 |
| CVE-2023-32005 |
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allo... |
Moderate |
nodejs-packaging |
否 |
完成修复 |
2023-09-11 |
2026-01-22 |
| CVE-2019-7819 |
Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
Moderate |
file |
是 |
完成修复 |
2023-09-11 |
2026-03-17 |
| CVE-2023-4875 |
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12 |
Moderate |
mutt |
是 |
完成修复 |
2023-09-09 |
2026-07-10 |
| CVE-2023-4874 |
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 |
Moderate |
mutt |
是 |
完成修复 |
2023-09-09 |
2026-07-10 |
| CVE-2023-41915 |
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition ... |
Important |
pmix |
否 |
完成修复 |
2023-09-09 |
2026-01-04 |
| CVE-2023-4807 |
Issue summary: The POLY1305 MAC (message authentication code) implementation \ncontains a bug that might corrupt the internal s... |
Important |
openssl-pkcs11, openssl |
否 |
完成修复 |
2023-09-08 |
2026-01-09 |
| CVE-2023-4585 |
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memo... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-4584 |
Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. So... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-4583 |
The Mozilla Foundation Security Advisory describes this flaw as: |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2026-01-24 |
| CVE-2023-4581 |
The Mozilla Foundation Security Advisory describes this flaw as: |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2026-01-24 |
| CVE-2023-4580 |
The Mozilla Foundation Security Advisory describes this flaw as: |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2026-01-24 |
| CVE-2023-4578 |
The Mozilla Foundation Security Advisory describes this flaw as: |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2026-01-24 |
| CVE-2023-4577 |
When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to enteri... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-4575 |
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-4574 |
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created a... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-4573 |
When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-afte... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-09-08 |
2025-12-30 |
| CVE-2023-41564 |
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary... |
Moderate |
cockpit |
是 |
完成修复 |
2023-09-08 |
2026-07-11 |
| CVE-2023-39322 |
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a mali... |
Important |
golang, container-tools:an8 |
是 |
完成修复 |
2023-09-08 |
2025-12-11 |
| CVE-2023-39321 |
Processing an incomplete post-handshake message for a QUIC connection can cause a panic. |
Important |
grafana, golang-dbus, container-tools:2.0, container-tools:3.0, container-tools:an8, git-lfs, golang |
是 |
完成修复 |
2023-09-08 |
2025-12-11 |
| CVE-2023-39320 |
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of... |
Important |
golang-dbus, golang |
是 |
完成修复 |
2023-09-08 |
2025-12-11 |
| CVE-2023-39319 |
The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within ... |
Moderate |
grafana, golang-dbus, golang, container-tools:an8 |
是 |
完成修复 |
2023-09-08 |
2025-12-11 |
| CVE-2023-39318 |
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in |