CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-1295 linux内核的io_uring存在time-of-checktotime-of-use漏洞,可导致提权,因为io_close被分成两部分,导致中�... Moderate kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-07-04 2026-01-07
CVE-2023-36053 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ... Important python-django 完成修复 2023-07-03 2026-01-04
CVE-2023-2727 Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. ... Moderate kubernetes 完成修复 2023-07-03 2026-03-25
CVE-2023-29405 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious mod... Important golang, go-toolset:an8 完成修复 2023-07-01 2025-12-11
CVE-2023-29404 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious mod... Important golang, go-toolset:an8 完成修复 2023-07-01 2025-12-11
CVE-2023-29403 On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dan... Important golang, go-toolset:an8 完成修复 2023-07-01 2025-12-11
CVE-2023-29402 The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a... Moderate golang, go-toolset:an8 完成修复 2023-07-01 2025-12-11
CVE-2023-2491 A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" func... Important emacs 完成修复 2023-07-01 2026-01-07
CVE-2023-2295 A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received... Important libreswan 完成修复 2023-07-01 2026-01-05
CVE-2023-20867 A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidenti... Low open-vm-tools 完成修复 2023-07-01 2026-07-10
CVE-2022-4285 An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version informat... Moderate gcc-toolset-12-binutils, binutils 完成修复 2023-07-01 2025-12-11
CVE-2022-39229 Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow o... Moderate grafana, grafana-pcp 完成修复 2023-07-01 2026-03-27
CVE-2022-37032 An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. Thi... Important frr 完成修复 2023-07-01 2026-01-07
CVE-2022-36227 In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL ... Moderate libarchive 完成修复 2023-07-01 2026-01-22
CVE-2022-36087 OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an at... Moderate python-oauthlib, fence-agents 完成修复 2023-07-01 2026-07-10
CVE-2022-3204 A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving sof... Important unbound 完成修复 2023-07-01 2026-01-06
CVE-2022-2879 Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocat... Moderate cockpit-composer, osbuild, container-tools:an8, osbuild-composer, golang 完成修复 2023-07-01 2025-12-11
CVE-2022-1615 In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. Moderate openchange, evolution-mapi, samba 完成修复 2023-07-01 2026-03-27
CVE-2021-46829 GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF f... Important gdk-pixbuf2 完成修复 2023-07-01 2026-01-07
CVE-2020-24736 Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a c... Moderate sqlite 完成修复 2023-07-01 2026-06-27
CVE-2023-30586 A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental ... Important noslate-anode, nodejs 完成修复 2023-06-30 2026-01-05
CVE-2023-2908 在Libtiff的tif_dir.c文件中发现空指针取消引用问题。此问题可能允许攻击者将精心制作的TIFF图像�... Moderate libtiff 完成修复 2023-06-29 2026-03-25
CVE-2023-2861 QEMU中的9p直通文件系统(9pfs)实现中发现了一个缺陷。9pfs服务器没有禁止在主机端打开特殊文件,... Moderate qemu-kvm, qemu 完成修复 2023-06-29 2025-12-19
CVE-2023-26966 当libtiff读取损坏的小端TIFF文件并将输出指定为大端时,libtiff4.5.0容易受到uv_encode()中缓冲区溢出... Moderate libtiff 完成修复 2023-06-29 2026-03-25
CVE-2023-25433 libtiff4.5.0容易通过/libtiff/tools/tiffcrop.c:8499受到缓冲区溢出的影响。tiffcrop中的rotateImage()后缓冲区�... Moderate libtiff 完成修复 2023-06-29 2026-03-25
CVE-2022-48503 A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code executi... Important webkitgtk, webkit2gtk3 完成修复 2023-06-29 2026-01-04
CVE-2023-36617 A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have spec... Moderate ruby, ruby:2.5 完成修复 2023-06-28 2026-07-09
CVE-2023-3439 A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resour... Moderate kernel 完成修复 2023-06-28 2026-01-06
CVE-2023-3390 A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. \n \nMisha... Moderate kernel, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-06-28 2026-01-07
CVE-2023-3389 Linux内核iouring子系统中的释放后使用漏洞可被利用来实现本地权限提升。 \n \n与链接超时竞争io... Moderate kernel 完成修复 2023-06-28 2026-01-07
CVE-2023-3359 An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return v... Moderate kernel 完成修复 2023-06-28 2026-01-07
CVE-2023-3357 A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to cr... Low kernel 完成修复 2023-06-28 2026-01-23
CVE-2023-3355 A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msmgem_submit.c code in the submit_lookup... Low kernel 完成修复 2023-06-28 2026-01-23
CVE-2023-3117 在linux内核的Netfilter子系统内,当添加一条新规则指向一个匿名集合时,会错误的执行nf_tables_rule... Important kernel 完成修复 2023-06-28 2025-12-05
CVE-2023-3090 A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege ... Important kernel 完成修复 2023-06-28 2025-12-05
CVE-2022-46408 Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manage... Moderate NetworkManager 完成修复 2023-06-28 2026-03-25
CVE-2022-46407 Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where O... Moderate NetworkManager 完成修复 2023-06-28 2026-03-25
CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows... Important php, php:7.4 完成修复 2023-06-28 2026-01-04
CVE-2022-31630 In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supp... Moderate php, php:7.4 完成修复 2023-06-28 2026-07-10
CVE-2022-31629 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard i... Moderate php, php:7.4 完成修复 2023-06-28 2026-07-10
CVE-2022-31628 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, ... Moderate php, php:7.4 完成修复 2023-06-28 2026-07-10
CVE-2023-2860 Linux内核中的SR-IPv6实现中发现越界读取漏洞。该缺陷存在于seg6属性的处理中。该问题是由于对用... Moderate kernel 完成修复 2023-06-27 2026-01-07
CVE-2023-3863 A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a lo... Moderate kernel 完成修复 2023-06-25 2026-01-07
CVE-2023-36660 The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. Moderate nettle 完成修复 2023-06-25 2026-03-25
CVE-2015-20109 end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent ... Moderate glibc 完成修复 2023-06-25 2025-12-11
CVE-2023-1206 当用户进行新型SYN洪水攻击时,Linux内核IPv6功能中的IPv6连接查找表中发现了哈希冲突缺陷。位于... Moderate kernel 完成修复 2023-06-24 2026-01-07
CVE-2023-3317 A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi ... Low kernel 完成修复 2023-06-23 2026-01-23
CVE-2023-32409 The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.... Important webkitgtk 完成修复 2023-06-23 2025-12-29
CVE-2023-32360 An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monter... Moderate cups 完成修复 2023-06-23 2026-07-13
CVE-2023-3212 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems ... Moderate kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-06-23 2026-01-07
CVE-2022-27652 cri-o中发现了一个缺陷,其中容器以非空默认权限错误地启动。Moby(Docker引擎)中发现了一个漏�... Moderate cri-o, docker 完成修复 2023-06-23 2026-07-10
CVE-2022-24836 Nokogiri是一个用于Ruby的开源XML和HTML库。Nokogiri=1.13.4。此问题没有已知的解决方法。 Important nokogiri 完成修复 2023-06-23 2026-01-05
CVE-2023-35788 linux的cls_flower模块存在越界写漏洞,可导致提权,已公开poc暂无exp,可以通过把cls_flower内核模块... Important kernel 完成修复 2023-06-22 2025-12-05
CVE-2023-34462 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance prot... Moderate log4j 完成修复 2023-06-22 2026-07-11
CVE-2023-3128 Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and ca... Moderate grafana 完成修复 2023-06-22 2026-01-22
CVE-2023-34241 OpenPrintingCUPS是一个基于标准的开源打印系统,适用于Linux和其他类Unix操作系统。从版本2.0.0开始�... Important cups 完成修复 2023-06-21 2026-01-06
CVE-2023-3358 在Linux内核的集成传感器集线器(ISH)驱动程序中发现了空指针取消引用。此问题可能会导致本地用... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-06-21 2026-01-07
CVE-2023-2911 如果在配置了stale-answer-enableyes;和stale-answer-client-timeout0;的BIND9解析器上达到了recursive-clients配额�... Important bind, bind-dyndb-ldap 完成修复 2023-06-21 2026-01-06
CVE-2023-2829 A named instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cach... Important bind 完成修复 2023-06-21 2026-01-06
CVE-2023-26115 All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an ins... Important grafana, pcs 完成修复 2023-06-21 2026-01-04
CVE-2023-25435 libtiff4.5.0容易通过位于/libtiff/tools/tiffcrop.c:3753的extractContigSamplesShifted8bits()受到缓冲区溢出的影响... Moderate libtiff 完成修复 2023-06-21 2026-03-25
CVE-2023-34981 ApacheTomcat11.0.0-M5、10.1.8、9.0.74和8.5.88中错误66512修复中的回归意味着,如果响应不包含任何HTTP标�... Important tomcat 完成修复 2023-06-20 2026-01-04
CVE-2023-3220 An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c ... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-06-20 2026-01-06
CVE-2023-30587 A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the bui... Important noslate-anode, nodejs, nodejs:20 完成修复 2023-06-20 2026-01-05
CVE-2023-30584 A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw rel... Important noslate-anode, nodejs, nodejs:20 完成修复 2023-06-20 2026-01-05
CVE-2023-30583 fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the --allow-fs-re... Moderate noslate-anode, nodejs 完成修复 2023-06-20 2026-07-10
CVE-2023-30582 A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allo... Moderate noslate-anode, nodejs 完成修复 2023-06-20 2026-07-10
CVE-2022-31212 31之前在dbus-broker中发现了一个问题。它依赖于c-uitl/c-shquote来解析DBus服务的Exec行。如果提供了恶... Important dbus-broker 完成修复 2023-06-20 2026-01-06
CVE-2022-25883 Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new... Moderate nodejs:18, nodejs, nodejs:16 完成修复 2023-06-20 2026-03-25
CVE-2020-20703 VIMv.8.1.2135中的缓冲区溢出漏洞允许远程攻击者通过操作数参数执行任意代码。 Low vim 完成修复 2023-06-20 2026-03-25
CVE-2023-35825 linux内核中存在设备移除之前没有清楚worker导致的uaf,影响版本2.6.39-rc1<=版本<6.4-rc1 Moderate kernel 完成修复 2023-06-19 2026-01-06
CVE-2023-34417 Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with eno... Important firefox 完成修复 2023-06-19 2025-12-30
CVE-2023-3312 A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during devi... Low kernel 完成修复 2023-06-19 2026-01-23
CVE-2023-3247 在8.0.29之前的PHP版本8.0.、8.1.20之前的8.1.、8.2.7之前的8.2.*中,当使用SOAPHTTP摘要身份验证时,不... Moderate php, php:8.0, php:7.4 完成修复 2023-06-19 2026-07-10
CVE-2023-3022 A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometime... Moderate kernel:4.19, kernel:5.10 完成修复 2023-06-19 2026-01-06
CVE-2023-29545 Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names wo... Moderate firefox, thunderbird 完成修复 2023-06-19 2026-01-24
CVE-2023-29542 A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file exten... Moderate firefox, thunderbird 完成修复 2023-06-19 2026-01-24
CVE-2023-29532 A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an ... Moderate firefox, thunderbird 完成修复 2023-06-19 2026-01-24
CVE-2023-29531 An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially e... Important firefox, thunderbird 完成修复 2023-06-19 2025-12-30
CVE-2022-31051 Semantic-release是一个开源npm包,用于自动化版本管理和包发布。在受影响的版本中,如果通常由语... Important cockpit-session-recording, cockpit, semantic-release, cockpit-appstream 完成修复 2023-06-19 2026-01-08
CVE-2019-25136 A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution a... Moderate firefox 完成修复 2023-06-19 2026-01-24
CVE-2023-35829 在6.3.2之前的Linux内核中发现了一个问题。在drivers/staging/media/rkvdec/rkvdec.c的rkvdec_remove中发现了释�... Moderate kernel 完成修复 2023-06-18 2026-01-06
CVE-2023-35828 在6.3.2之前的Linux内核中发现了一个问题。在drivers/usb/gadget/udc/renesas_usb3.c的renesas_usb3_remove中发现�... Moderate kernel 完成修复 2023-06-18 2026-01-06
CVE-2023-35827 从6.3.8开始,在Linux内核中发现了一个问题。在drivers/net/ethernet/renesas/ravb_main.c的ravb_remove中发现了... Moderate kernel 完成修复 2023-06-18 2026-01-06
CVE-2023-35826 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/... Moderate kernel 完成修复 2023-06-18 2026-01-06
CVE-2023-3316 TIFFClose()中的NULL指针取消引用是由于在指定区域时无法打开输出文件(不存在的路径或需要/dev/null... Moderate libtiff 完成修复 2023-06-18 2026-01-22
CVE-2023-35790 An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a... Moderate firefox 完成修复 2023-06-16 2026-01-24
CVE-2023-35789 An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be ente... Moderate librabbitmq 完成修复 2023-06-16 2026-07-11
CVE-2023-3268 An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the r... Important kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-06-16 2025-12-05
CVE-2023-32067 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the ... Important nodejs:18, nodejs:16, c-ares 完成修复 2023-06-16 2026-01-10
CVE-2023-2431 A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost ... Low kubernetes 完成修复 2023-06-16 2026-03-25
CVE-2023-3138 libX11中发现漏洞。出现安全漏洞的原因是libX11的src/InitExt.c中的函数不检查为请求、事件或错误ID�... Moderate libX11 完成修复 2023-06-15 2026-03-25
CVE-2023-35116 DISPUTED jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a ... Moderate jackson-databind 完成修复 2023-06-14 2026-07-09
CVE-2023-2976 Use of Java's default temporary directory for file creation in FileBackedOutputStream in Google Guava versions 1.0 to 31.1 on... Moderate guava 完成修复 2023-06-14 2026-01-22
CVE-2023-26965 LibTIFF到4.5.0中的tools/tiffcrop.c中的loadImage()在释放后通过精心制作的TIFF图像进行基于堆的使用。 Moderate libtiff 完成修复 2023-06-14 2026-03-25
CVE-2023-25434 libtiff4.5.0容易通过/libtiff/tools/tiffcrop.c:3215处的extractContigSamplesBytes()受到缓冲区溢出的影响。 Moderate libtiff 完成修复 2023-06-14 2026-03-25
CVE-2023-32032 .NET and Visual Studio Elevation of Privilege Vulnerability Important dotnet, dotnet7.0 完成修复 2023-06-13 2025-12-05
CVE-2023-31439 DISPUTED An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file ... Moderate systemd 完成修复 2023-06-13 2026-03-25
CVE-2023-31438 DISPUTED An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing s... Moderate systemd 完成修复 2023-06-13 2026-03-25
CVE-2023-31437 DISPUTED An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not a... Moderate systemd 完成修复 2023-06-13 2026-03-25

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""