CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-38665 Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash). Moderate nasm 完成修复 2023-08-22 2026-03-26
CVE-2022-48571 memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP. Important memcached 完成修复 2023-08-22 2025-12-30
CVE-2022-48566 An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were po... Important python2, python3, python-alembic, python 完成修复 2023-08-22 2026-01-09
CVE-2022-48565 An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declara... Moderate python2, python3, python-alembic, python, python27:2.7 完成修复 2023-08-22 2026-03-26
CVE-2022-48564 read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when proces... Moderate python2, python3, python 完成修复 2023-08-22 2026-03-26
CVE-2022-48560 A use-after-free exists in Python through 3.9 via heappushpop in heapq. Important python2, python3, python-alembic, python, python27:2.7 完成修复 2023-08-22 2026-01-09
CVE-2022-48554 File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source pro... Moderate file, file-roller 完成修复 2023-08-22 2026-03-26
CVE-2022-48522 In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local priv... Moderate perl-any-uri-escape, perl 完成修复 2023-08-22 2026-03-26
CVE-2022-47011 在Binutils2.34至2.38中,stabs.c中的函数parse_stab_struct_fields发现了一个问题,该问题允许攻击者因内�... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-47010 Binutils2.34至2.38中的prdbg.c中的函数pr_function_type发现了一个问题,该问题允许攻击者因内存泄漏而�... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-47008 Binutils2.34至2.38中的bucomm.c中的函数make_tempdir和make_tempname发现了一个问题,允许攻击者因内存泄漏... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-47007 在Binutils2.34至2.38中,stabs.c中的函数Stab_demangle_v3_arg发现了一个问题,该问题允许攻击者因内存泄... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-45703 2.40之前的binutilsreadelf中存在堆缓冲区溢出漏洞,通过文件readelf.c中的函数display_debug_section实现。 Important binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-44840 2.40之前的binutilsreadelf中存在堆缓冲区溢出漏洞,通过文件readelf.c中的函数find_section_in_set实现。 Important binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-44730 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apa... Moderate batik 完成修复 2023-08-22 2026-07-11
CVE-2022-44729 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apa... Moderate batik 完成修复 2023-08-22 2026-07-11
CVE-2022-43357 Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g2... Important sassc 完成修复 2023-08-22 2025-12-29
CVE-2022-40433 An issue was discovered in function ciMethodBlocks::make_block_at in Oracle JDK (HotSpot VM) 11, 17 and OpenJDK (HotSpot VM) 8,... Moderate java-1.8.0-openjdk 完成修复 2023-08-22 2025-12-05
CVE-2022-40090 An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via cr... Moderate libtiff 完成修复 2023-08-22 2026-01-22
CVE-2022-38349 An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because ... Moderate poppler 完成修复 2023-08-22 2026-07-10
CVE-2022-37052 Poppler22.07.0中的可达Object::getString断言允许攻击者因markObject中的故障而导致拒绝服务。 Moderate poppler 完成修复 2023-08-22 2026-03-27
CVE-2022-37051 Poppler22.07.0中发现了一个问题。存在可到达的中止,这会导致拒绝服务,因为pdfunite.cc中的主要功... Moderate poppler 完成修复 2023-08-22 2026-03-27
CVE-2022-37050 在Poppler22.07.0中,PDFDoc.c中的PDFDoc::savePageAs允许攻击者通过制作在getCatalog处理中错误处理外部参�... Moderate poppler 完成修复 2023-08-22 2026-03-27
CVE-2022-35206 Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c. Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-35205 Binutilsreadelf2.38.50中发现了一个问题,函数display_debug_names中的可达断言失败允许攻击者导致拒绝�... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2022-34038 DISPUTED Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go.... Moderate docker 完成修复 2023-08-22 2026-03-26
CVE-2022-29654 Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of ser... Moderate nasm 完成修复 2023-08-22 2026-01-22
CVE-2022-26592 Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. Important libsass 完成修复 2023-08-22 2026-01-05
CVE-2021-34193 Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs. Important opensc 完成修复 2023-08-22 2026-01-05
CVE-2021-30047 VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed. Important vsftpd 完成修复 2023-08-22 2025-12-29
CVE-2021-29390 libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c. Important libjpeg-turbo 完成修复 2023-08-22 2026-01-06
CVE-2020-35357 A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), v... Moderate gsl 完成修复 2023-08-22 2026-03-26
CVE-2020-35342 GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which ... Important binutils 完成修复 2023-08-22 2025-12-11
CVE-2020-27418 A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_inv... Moderate kernel 完成修复 2023-08-22 2026-01-07
CVE-2020-23804 Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via craft... Important poppler, poppler-data 完成修复 2023-08-22 2026-01-04
CVE-2020-23793 An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulne... Important spice-vdagent, spice 完成修复 2023-08-22 2026-01-04
CVE-2020-22916 XZ5.2.5中发现的一个问题允许攻击者通过解压缩精心设计的文件来导致拒绝服务。注意:截至2023�... Moderate xz 完成修复 2023-08-22 2026-03-26
CVE-2020-22628 Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp. Moderate LibRaw 完成修复 2023-08-22 2026-03-26
CVE-2020-22570 Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command. Important memcached 完成修复 2023-08-22 2026-01-04
CVE-2020-22219 Buffer Overflow vulnerability in function bitwritergrow in flac before 1.4.0 allows remote attackers to run arbitrary code vi... Important flac 完成修复 2023-08-22 2026-01-07
CVE-2020-22217 Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. Moderate c-ares 完成修复 2023-08-22 2026-01-22
CVE-2020-21896 A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPD... Moderate mupdf 完成修复 2023-08-22 2026-07-13
CVE-2020-21890 Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attacke... Important ghostscript 完成修复 2023-08-22 2026-01-06
CVE-2020-21710 A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers ... Moderate ghostscript 完成修复 2023-08-22 2026-03-26
CVE-2020-21687 Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of servic... Moderate nasm 完成修复 2023-08-22 2026-03-26
CVE-2020-21686 A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attac... Moderate nasm 完成修复 2023-08-22 2026-01-22
CVE-2020-21685 Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of ... Moderate nasm 完成修复 2023-08-22 2026-03-26
CVE-2020-21583 An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the... Moderate util-linux 完成修复 2023-08-22 2026-03-26
CVE-2020-21528 A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers... Moderate nasm 完成修复 2023-08-22 2026-03-26
CVE-2020-21469 DISPUTED An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending ... Low libpq 完成修复 2023-08-22 2026-03-26
CVE-2020-21047 The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerabi... Moderate elfutils 完成修复 2023-08-22 2026-03-26
CVE-2020-19909 DISPUTED Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many... Low curl 完成修复 2023-08-22 2026-03-26
CVE-2020-19726 An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to sy... Important binutils 完成修复 2023-08-22 2025-12-11
CVE-2020-19724 A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of se... Moderate binutils 完成修复 2023-08-22 2025-12-11
CVE-2020-19190 Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denia... Moderate ncurses 完成修复 2023-08-22 2026-03-26
CVE-2020-19189 Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attacker... Moderate ncurses 完成修复 2023-08-22 2026-03-26
CVE-2020-19188 Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause ... Moderate ncurses 完成修复 2023-08-22 2026-03-26
CVE-2020-19187 ncurses6.1中的progs/dump_entry.c:1100中的fmt_entry函数中存在缓冲区溢出漏洞,允许远程攻击者通过精心�... Moderate ncurses 完成修复 2023-08-22 2026-03-26
CVE-2020-19185 ncurses6.1中的progs/dump_entry.c:1373中的one_one_mapping函数中存在缓冲区溢出漏洞,允许远程攻击者通过�... Moderate ncurses 完成修复 2023-08-22 2026-03-26
CVE-2020-18839 poppler0.75.0中的HtmlOutputDev::page中的缓冲区溢出漏洞允许攻击者造成拒绝服务。 Moderate poppler 完成修复 2023-08-22 2026-03-27
CVE-2020-18831 Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a deni... Important exiv2 完成修复 2023-08-22 2026-01-07
CVE-2020-18780 A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of ser... Moderate nasm 完成修复 2023-08-22 2026-03-26
CVE-2020-18770 An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial... Moderate zziplib 完成修复 2023-08-22 2026-03-27
CVE-2020-18768 There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denia... Moderate libtiff 完成修复 2023-08-22 2026-03-26
CVE-2020-18652 Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of serv... Moderate exempi 完成修复 2023-08-22 2026-03-26
CVE-2020-18651 Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote atta... Moderate exempi 完成修复 2023-08-22 2026-07-11
CVE-2023-32002 The use of Module._load() can bypass the policy mechanism and require modules outside of the policy.json definition for a giv... Important noslate-anode, nodejs, nodejs:16, nodejs:18 完成修复 2023-08-21 2026-01-05
CVE-2022-46751 Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Softwa... Important apache-ivy 完成修复 2023-08-21 2026-01-04
CVE-2023-4459 linux内核vmxnet3模块中vmxnet3_rq_cleanup存在空指针解引用,可导致DOS,影响版本2.6.32-rc5<=版本<5.18,�... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-08-20 2026-01-07
CVE-2023-4451 Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Moderate cockpit 完成修复 2023-08-20 2026-07-11
CVE-2023-25775 适用于Linux版本1.9.30之前的英特尔(R)以太网控制器RDMA驱动程序中的访问控制不当可能会允许未经�... Moderate kernel 完成修复 2023-08-20 2026-01-22
CVE-2023-20588 某些AMD处理器上的除零错误可能会返回推测数据,从而导致机密性丢失。 Moderate kernel:4.19, kernel, kernel:5.10 完成修复 2023-08-19 2026-01-07
CVE-2023-4433 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Important cockpit 完成修复 2023-08-18 2026-01-08
CVE-2023-4432 Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Important cockpit 完成修复 2023-08-18 2026-01-08
CVE-2023-4422 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Moderate cockpit 完成修复 2023-08-18 2026-07-11
CVE-2023-38497 Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust pr... Moderate rust, rust-toolset:an8 完成修复 2023-08-18 2025-12-16
CVE-2023-4394 A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux Kernel.... Moderate kernel 完成修复 2023-08-17 2026-01-07
CVE-2023-4395 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. Important cockpit 完成修复 2023-08-16 2026-01-08
CVE-2023-4389 由于引用计数双减,Linux内核中btrfs文件系统的fs/btrfs/disk-io.c中的btrfs_get_root_ref中发现了一个缺陷... Moderate kernel 完成修复 2023-08-16 2026-01-07
CVE-2023-4387 Linux内核中VMwarevmxnet3以太网网卡驱动程序的drivers/net/vmxnet3/vmxnet3_drv.c中的vmxnet3_rq_alloc_rx_buf中发�... Moderate kernel 完成修复 2023-08-16 2026-01-07
CVE-2023-4385 在Linux内核的日志文件系统(JFS)的fs/jfs/jfs_dmap.c中的dbFree中发现了NULL指针取消引用缺陷。由于缺少... Moderate kernel 完成修复 2023-08-16 2026-01-07
CVE-2023-40340 Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm ... Important nodejs 完成修复 2023-08-16 2026-01-04
CVE-2023-38180 .NET and Visual Studio Denial of Service Vulnerability Important dotnet6.0 完成修复 2023-08-16 2025-12-05
CVE-2023-35390 .NET and Visual Studio Remote Code Execution Vulnerability Important dotnet6.0 完成修复 2023-08-16 2025-12-05
CVE-2023-28938 mdadm-4.2-rc2版本之前的某些英特尔(R)SSD工具软件中不受控制的资源消耗可能允许特权用户通过本地... Moderate mdadm 完成修复 2023-08-16 2026-03-26
CVE-2023-28736 mdadm-4.2-rc2版本之前的某些英特尔(R)SSD工具软件中的缓冲区溢出可能允许特权用户通过本地访问实... Moderate mdadm 完成修复 2023-08-16 2026-03-26
CVE-2023-39975 1.21.2之前的MITKerberos5(又名krb5)1.21中的kdc/do_tgs_req.c具有双重释放,如果经过身份验证的用户可�... Moderate krb5 完成修复 2023-08-15 2026-01-22
CVE-2023-32006 The use of module.constructor.createRequire() can bypass the policy mechanism and require modules outside of the policy.json ... Important noslate-anode, nodejs, nodejs:16, nodejs:18 完成修复 2023-08-15 2026-01-05
CVE-2023-32004 A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw rel... Important nodejs 完成修复 2023-08-15 2026-01-06
CVE-2023-32003 fs.mkdtemp() and fs.mkdtempSync() can be used to bypass the permission model check using a path traversal attack. This flaw... Moderate nodejs-packaging 完成修复 2023-08-15 2026-01-22
CVE-2023-4321 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. Important cockpit 完成修复 2023-08-14 2026-01-08
CVE-2023-4134 From the upstream fix below: The watchdog_timer can schedule tx_timeout_task and watchdog_work can also arm watchdog_timer [..]... Moderate kernel 完成修复 2023-08-14 2026-01-07
CVE-2023-4133 A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detac... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-08-14 2026-01-07
CVE-2023-40360 QEMU到8.0.4会访问hw/nvme/ctrl.c中nvme_directive_receive中的NULL指针,因为在检查是否启用灵活数据放置之... Moderate qemu 完成修复 2023-08-14 2025-12-18
CVE-2023-40359 xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphan... Low xterm 完成修复 2023-08-14 2026-01-22
CVE-2023-28198 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ve... Important webkitgtk, webkit2gtk3 完成修复 2023-08-14 2026-01-04
CVE-2023-21264 In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the... Moderate kernel 完成修复 2023-08-14 2026-01-07
CVE-2023-40283 An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-a... Moderate kernel 完成修复 2023-08-13 2026-01-07
CVE-2020-36023 freedesktoppoppler版本20.12.1中发现了一个问题,允许远程攻击者通过精心制作的.pdf文件对FoFiType1C::cv... Moderate poppler 完成修复 2023-08-13 2026-07-10
CVE-2023-39418 A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security po... Moderate libpq, ghostscript, postgresql, postgresql:15 完成修复 2023-08-11 2026-07-10

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""