CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-41900 Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to wea... Low jetty 完成修复 2023-09-15 2026-07-09
CVE-2023-40167 Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the ... Moderate jetty 完成修复 2023-09-15 2026-07-09
CVE-2023-36479 Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very speci... Low jetty 完成修复 2023-09-15 2026-07-09
CVE-2023-42503 Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue... Moderate apache-commons-compress 完成修复 2023-09-14 2025-12-05
CVE-2023-35824 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm11... Moderate kernel 完成修复 2023-09-14 2026-01-07
CVE-2023-35823 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/sa... Moderate kernel 完成修复 2023-09-14 2026-01-07
CVE-2023-4421 This patch defeats Bleichenbacher by not trying to hide the size of the\ndecrypted text, but to hide if the text succeeded for ... Moderate python-nss 完成修复 2023-09-13 2026-06-26
CVE-2023-41081 Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such... Moderate mod_jk, httpd 完成修复 2023-09-13 2026-07-10
CVE-2023-36799 .NET Core and Visual Studio Denial of Service Vulnerability Moderate dotnet6.0 完成修复 2023-09-13 2025-12-05
CVE-2023-3255 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an... Moderate virt-what, virt:an, qemu-kvm, qemu 完成修复 2023-09-13 2025-12-18
CVE-2023-4921 A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege e... Moderate kernel 完成修复 2023-09-12 2026-01-22
CVE-2023-4582 Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating... Important firefox, thunderbird 完成修复 2023-09-11 2026-01-04
CVE-2023-4576 On Windows, an integer overflow could occur in RecordedSourceSurfaceCreation which resulted in a heap buffer overflow potenti... Important firefox, thunderbird 完成修复 2023-09-11 2025-12-30
CVE-2023-32558 The use of the deprecated API process.binding() can bypass the permission model through path traversal. \n \nThis vulnerabil... Important nodejs 完成修复 2023-09-11 2026-01-06
CVE-2023-32005 A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allo... Moderate nodejs-packaging 完成修复 2023-09-11 2026-01-22
CVE-2019-7819 Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to... Moderate file 完成修复 2023-09-11 2026-03-17
CVE-2023-4875 Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12 Moderate mutt 完成修复 2023-09-09 2026-07-10
CVE-2023-4874 Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 Moderate mutt 完成修复 2023-09-09 2026-07-10
CVE-2023-41915 OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition ... Important pmix 完成修复 2023-09-09 2026-01-04
CVE-2023-4807 Issue summary: The POLY1305 MAC (message authentication code) implementation \ncontains a bug that might corrupt the internal s... Important openssl-pkcs11, openssl 完成修复 2023-09-08 2026-01-09
CVE-2023-4585 Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memo... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-4584 Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. So... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-4583 The Mozilla Foundation Security Advisory describes this flaw as: Moderate firefox, thunderbird 完成修复 2023-09-08 2026-01-24
CVE-2023-4581 The Mozilla Foundation Security Advisory describes this flaw as: Moderate firefox, thunderbird 完成修复 2023-09-08 2026-01-24
CVE-2023-4580 The Mozilla Foundation Security Advisory describes this flaw as: Moderate firefox, thunderbird 完成修复 2023-09-08 2026-01-24
CVE-2023-4578 The Mozilla Foundation Security Advisory describes this flaw as: Moderate firefox, thunderbird 完成修复 2023-09-08 2026-01-24
CVE-2023-4577 When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to enteri... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-4575 When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-4574 When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created a... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-4573 When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-afte... Important firefox, thunderbird 完成修复 2023-09-08 2025-12-30
CVE-2023-41564 An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary... Moderate cockpit 完成修复 2023-09-08 2026-07-11
CVE-2023-39322 QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a mali... Important golang, container-tools:an8 完成修复 2023-09-08 2025-12-11
CVE-2023-39321 Processing an incomplete post-handshake message for a QUIC connection can cause a panic. Important grafana, golang-dbus, container-tools:2.0, container-tools:3.0, container-tools:an8, git-lfs, golang 完成修复 2023-09-08 2025-12-11
CVE-2023-39320 The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of... Important golang-dbus, golang 完成修复 2023-09-08 2025-12-11
CVE-2023-39319 The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within ... Moderate grafana, golang-dbus, golang, container-tools:an8 完成修复 2023-09-08 2025-12-11
CVE-2023-39318 The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in

results matching ""

    No results matching ""

    results matching ""

      No results matching ""