| CVE-2023-1295 |
linux内核的io_uring存在time-of-checktotime-of-use漏洞,可导致提权,因为io_close被分成两部分,导致中�... |
Moderate |
kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2023-07-04 |
2026-01-07 |
| CVE-2023-36053 |
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ... |
Important |
python-django |
否 |
完成修复 |
2023-07-03 |
2026-01-04 |
| CVE-2023-2727 |
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. ... |
Moderate |
kubernetes |
是 |
完成修复 |
2023-07-03 |
2026-03-25 |
| CVE-2023-29405 |
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious mod... |
Important |
golang, go-toolset:an8 |
是 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2023-29404 |
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious mod... |
Important |
golang, go-toolset:an8 |
是 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2023-29403 |
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dan... |
Important |
golang, go-toolset:an8 |
是 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2023-29402 |
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a... |
Moderate |
golang, go-toolset:an8 |
是 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2023-2491 |
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" func... |
Important |
emacs |
否 |
完成修复 |
2023-07-01 |
2026-01-07 |
| CVE-2023-2295 |
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received... |
Important |
libreswan |
否 |
完成修复 |
2023-07-01 |
2026-01-05 |
| CVE-2023-20867 |
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidenti... |
Low |
open-vm-tools |
是 |
完成修复 |
2023-07-01 |
2026-07-10 |
| CVE-2022-4285 |
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version informat... |
Moderate |
gcc-toolset-12-binutils, binutils |
否 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2022-39229 |
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow o... |
Moderate |
grafana, grafana-pcp |
是 |
完成修复 |
2023-07-01 |
2026-03-27 |
| CVE-2022-37032 |
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. Thi... |
Important |
frr |
否 |
完成修复 |
2023-07-01 |
2026-01-07 |
| CVE-2022-36227 |
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL ... |
Moderate |
libarchive |
否 |
完成修复 |
2023-07-01 |
2026-01-22 |
| CVE-2022-36087 |
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an at... |
Moderate |
python-oauthlib, fence-agents |
是 |
完成修复 |
2023-07-01 |
2026-07-10 |
| CVE-2022-3204 |
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving sof... |
Important |
unbound |
否 |
完成修复 |
2023-07-01 |
2026-01-06 |
| CVE-2022-2879 |
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocat... |
Moderate |
cockpit-composer, osbuild, container-tools:an8, osbuild-composer, golang |
是 |
完成修复 |
2023-07-01 |
2025-12-11 |
| CVE-2022-1615 |
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. |
Moderate |
openchange, evolution-mapi, samba |
是 |
完成修复 |
2023-07-01 |
2026-03-27 |
| CVE-2021-46829 |
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF f... |
Important |
gdk-pixbuf2 |
否 |
完成修复 |
2023-07-01 |
2026-01-07 |
| CVE-2020-24736 |
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a c... |
Moderate |
sqlite |
是 |
完成修复 |
2023-07-01 |
2026-06-27 |
| CVE-2023-30586 |
A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental ... |
Important |
noslate-anode, nodejs |
否 |
完成修复 |
2023-06-30 |
2026-01-05 |
| CVE-2023-2908 |
在Libtiff的tif_dir.c文件中发现空指针取消引用问题。此问题可能允许攻击者将精心制作的TIFF图像�... |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-29 |
2026-03-25 |
| CVE-2023-2861 |
QEMU中的9p直通文件系统(9pfs)实现中发现了一个缺陷。9pfs服务器没有禁止在主机端打开特殊文件,... |
Moderate |
qemu-kvm, qemu |
否 |
完成修复 |
2023-06-29 |
2025-12-19 |
| CVE-2023-26966 |
当libtiff读取损坏的小端TIFF文件并将输出指定为大端时,libtiff4.5.0容易受到uv_encode()中缓冲区溢出... |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-29 |
2026-03-25 |
| CVE-2023-25433 |
libtiff4.5.0容易通过/libtiff/tools/tiffcrop.c:8499受到缓冲区溢出的影响。tiffcrop中的rotateImage()后缓冲区�... |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-29 |
2026-03-25 |
| CVE-2022-48503 |
A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code executi... |
Important |
webkitgtk, webkit2gtk3 |
否 |
完成修复 |
2023-06-29 |
2026-01-04 |
| CVE-2023-36617 |
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have spec... |
Moderate |
ruby, ruby:2.5 |
是 |
完成修复 |
2023-06-28 |
2026-07-09 |
| CVE-2023-3439 |
A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resour... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-28 |
2026-01-06 |
| CVE-2023-3390 |
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. \n \nMisha... |
Moderate |
kernel, kernel(RHCK)4.18, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2023-06-28 |
2026-01-07 |
| CVE-2023-3389 |
Linux内核iouring子系统中的释放后使用漏洞可被利用来实现本地权限提升。 \n \n与链接超时竞争io... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-28 |
2026-01-07 |
| CVE-2023-3359 |
An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return v... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-28 |
2026-01-07 |
| CVE-2023-3357 |
A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to cr... |
Low |
kernel |
是 |
完成修复 |
2023-06-28 |
2026-01-23 |
| CVE-2023-3355 |
A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msmgem_submit.c code in the submit_lookup... |
Low |
kernel |
是 |
完成修复 |
2023-06-28 |
2026-01-23 |
| CVE-2023-3117 |
在linux内核的Netfilter子系统内,当添加一条新规则指向一个匿名集合时,会错误的执行nf_tables_rule... |
Important |
kernel |
否 |
完成修复 |
2023-06-28 |
2025-12-05 |
| CVE-2023-3090 |
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege ... |
Important |
kernel |
否 |
完成修复 |
2023-06-28 |
2025-12-05 |
| CVE-2022-46408 |
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manage... |
Moderate |
NetworkManager |
是 |
完成修复 |
2023-06-28 |
2026-03-25 |
| CVE-2022-46407 |
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where O... |
Moderate |
NetworkManager |
是 |
完成修复 |
2023-06-28 |
2026-03-25 |
| CVE-2022-37454 |
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows... |
Important |
php, php:7.4 |
否 |
完成修复 |
2023-06-28 |
2026-01-04 |
| CVE-2022-31630 |
In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supp... |
Moderate |
php, php:7.4 |
是 |
完成修复 |
2023-06-28 |
2026-07-10 |
| CVE-2022-31629 |
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard i... |
Moderate |
php, php:7.4 |
是 |
完成修复 |
2023-06-28 |
2026-07-10 |
| CVE-2022-31628 |
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, ... |
Moderate |
php, php:7.4 |
是 |
完成修复 |
2023-06-28 |
2026-07-10 |
| CVE-2023-2860 |
Linux内核中的SR-IPv6实现中发现越界读取漏洞。该缺陷存在于seg6属性的处理中。该问题是由于对用... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-27 |
2026-01-07 |
| CVE-2023-3863 |
A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a lo... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-25 |
2026-01-07 |
| CVE-2023-36660 |
The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. |
Moderate |
nettle |
是 |
完成修复 |
2023-06-25 |
2026-03-25 |
| CVE-2015-20109 |
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent ... |
Moderate |
glibc |
否 |
完成修复 |
2023-06-25 |
2025-12-11 |
| CVE-2023-1206 |
当用户进行新型SYN洪水攻击时,Linux内核IPv6功能中的IPv6连接查找表中发现了哈希冲突缺陷。位于... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-24 |
2026-01-07 |
| CVE-2023-3317 |
A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi ... |
Low |
kernel |
是 |
完成修复 |
2023-06-23 |
2026-01-23 |
| CVE-2023-32409 |
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.... |
Important |
webkitgtk |
否 |
完成修复 |
2023-06-23 |
2025-12-29 |
| CVE-2023-32360 |
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monter... |
Moderate |
cups |
是 |
完成修复 |
2023-06-23 |
2026-07-13 |
| CVE-2023-3212 |
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems ... |
Moderate |
kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2023-06-23 |
2026-01-07 |
| CVE-2022-27652 |
cri-o中发现了一个缺陷,其中容器以非空默认权限错误地启动。Moby(Docker引擎)中发现了一个漏�... |
Moderate |
cri-o, docker |
是 |
完成修复 |
2023-06-23 |
2026-07-10 |
| CVE-2022-24836 |
Nokogiri是一个用于Ruby的开源XML和HTML库。Nokogiri=1.13.4。此问题没有已知的解决方法。 |
Important |
nokogiri |
否 |
完成修复 |
2023-06-23 |
2026-01-05 |
| CVE-2023-35788 |
linux的cls_flower模块存在越界写漏洞,可导致提权,已公开poc暂无exp,可以通过把cls_flower内核模块... |
Important |
kernel |
否 |
完成修复 |
2023-06-22 |
2025-12-05 |
| CVE-2023-34462 |
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance prot... |
Moderate |
log4j |
是 |
完成修复 |
2023-06-22 |
2026-07-11 |
| CVE-2023-3128 |
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and ca... |
Moderate |
grafana |
否 |
完成修复 |
2023-06-22 |
2026-01-22 |
| CVE-2023-34241 |
OpenPrintingCUPS是一个基于标准的开源打印系统,适用于Linux和其他类Unix操作系统。从版本2.0.0开始�... |
Important |
cups |
否 |
完成修复 |
2023-06-21 |
2026-01-06 |
| CVE-2023-3358 |
在Linux内核的集成传感器集线器(ISH)驱动程序中发现了空指针取消引用。此问题可能会导致本地用... |
Moderate |
kernel:4.19, kernel:6.6, kernel, kernel:5.10 |
否 |
完成修复 |
2023-06-21 |
2026-01-07 |
| CVE-2023-2911 |
如果在配置了stale-answer-enableyes;和stale-answer-client-timeout0;的BIND9解析器上达到了recursive-clients配额�... |
Important |
bind, bind-dyndb-ldap |
否 |
完成修复 |
2023-06-21 |
2026-01-06 |
| CVE-2023-2829 |
A named instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cach... |
Important |
bind |
否 |
完成修复 |
2023-06-21 |
2026-01-06 |
| CVE-2023-26115 |
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an ins... |
Important |
grafana, pcs |
否 |
完成修复 |
2023-06-21 |
2026-01-04 |
| CVE-2023-25435 |
libtiff4.5.0容易通过位于/libtiff/tools/tiffcrop.c:3753的extractContigSamplesShifted8bits()受到缓冲区溢出的影响... |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-21 |
2026-03-25 |
| CVE-2023-34981 |
ApacheTomcat11.0.0-M5、10.1.8、9.0.74和8.5.88中错误66512修复中的回归意味着,如果响应不包含任何HTTP标�... |
Important |
tomcat |
否 |
完成修复 |
2023-06-20 |
2026-01-04 |
| CVE-2023-3220 |
An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c ... |
Moderate |
kernel:4.19, kernel:6.6, kernel, kernel:5.10 |
否 |
完成修复 |
2023-06-20 |
2026-01-06 |
| CVE-2023-30587 |
A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the bui... |
Important |
noslate-anode, nodejs, nodejs:20 |
否 |
完成修复 |
2023-06-20 |
2026-01-05 |
| CVE-2023-30584 |
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw rel... |
Important |
noslate-anode, nodejs, nodejs:20 |
否 |
完成修复 |
2023-06-20 |
2026-01-05 |
| CVE-2023-30583 |
fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the --allow-fs-re... |
Moderate |
noslate-anode, nodejs |
是 |
完成修复 |
2023-06-20 |
2026-07-10 |
| CVE-2023-30582 |
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allo... |
Moderate |
noslate-anode, nodejs |
是 |
完成修复 |
2023-06-20 |
2026-07-10 |
| CVE-2022-31212 |
31之前在dbus-broker中发现了一个问题。它依赖于c-uitl/c-shquote来解析DBus服务的Exec行。如果提供了恶... |
Important |
dbus-broker |
否 |
完成修复 |
2023-06-20 |
2026-01-06 |
| CVE-2022-25883 |
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new... |
Moderate |
nodejs:18, nodejs, nodejs:16 |
是 |
完成修复 |
2023-06-20 |
2026-03-25 |
| CVE-2020-20703 |
VIMv.8.1.2135中的缓冲区溢出漏洞允许远程攻击者通过操作数参数执行任意代码。 |
Low |
vim |
是 |
完成修复 |
2023-06-20 |
2026-03-25 |
| CVE-2023-35825 |
linux内核中存在设备移除之前没有清楚worker导致的uaf,影响版本2.6.39-rc1<=版本<6.4-rc1 |
Moderate |
kernel |
否 |
完成修复 |
2023-06-19 |
2026-01-06 |
| CVE-2023-34417 |
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with eno... |
Important |
firefox |
否 |
完成修复 |
2023-06-19 |
2025-12-30 |
| CVE-2023-3312 |
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during devi... |
Low |
kernel |
是 |
完成修复 |
2023-06-19 |
2026-01-23 |
| CVE-2023-3247 |
在8.0.29之前的PHP版本8.0.、8.1.20之前的8.1.、8.2.7之前的8.2.*中,当使用SOAPHTTP摘要身份验证时,不... |
Moderate |
php, php:8.0, php:7.4 |
是 |
完成修复 |
2023-06-19 |
2026-07-10 |
| CVE-2023-3022 |
A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometime... |
Moderate |
kernel:4.19, kernel:5.10 |
否 |
完成修复 |
2023-06-19 |
2026-01-06 |
| CVE-2023-29545 |
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names wo... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-06-19 |
2026-01-24 |
| CVE-2023-29542 |
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file exten... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-06-19 |
2026-01-24 |
| CVE-2023-29532 |
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an ... |
Moderate |
firefox, thunderbird |
否 |
完成修复 |
2023-06-19 |
2026-01-24 |
| CVE-2023-29531 |
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially e... |
Important |
firefox, thunderbird |
否 |
完成修复 |
2023-06-19 |
2025-12-30 |
| CVE-2022-31051 |
Semantic-release是一个开源npm包,用于自动化版本管理和包发布。在受影响的版本中,如果通常由语... |
Important |
cockpit-session-recording, cockpit, semantic-release, cockpit-appstream |
否 |
完成修复 |
2023-06-19 |
2026-01-08 |
| CVE-2019-25136 |
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution a... |
Moderate |
firefox |
否 |
完成修复 |
2023-06-19 |
2026-01-24 |
| CVE-2023-35829 |
在6.3.2之前的Linux内核中发现了一个问题。在drivers/staging/media/rkvdec/rkvdec.c的rkvdec_remove中发现了释�... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-18 |
2026-01-06 |
| CVE-2023-35828 |
在6.3.2之前的Linux内核中发现了一个问题。在drivers/usb/gadget/udc/renesas_usb3.c的renesas_usb3_remove中发现�... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-18 |
2026-01-06 |
| CVE-2023-35827 |
从6.3.8开始,在Linux内核中发现了一个问题。在drivers/net/ethernet/renesas/ravb_main.c的ravb_remove中发现了... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-18 |
2026-01-06 |
| CVE-2023-35826 |
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/... |
Moderate |
kernel |
否 |
完成修复 |
2023-06-18 |
2026-01-06 |
| CVE-2023-3316 |
TIFFClose()中的NULL指针取消引用是由于在指定区域时无法打开输出文件(不存在的路径或需要/dev/null... |
Moderate |
libtiff |
否 |
完成修复 |
2023-06-18 |
2026-01-22 |
| CVE-2023-35790 |
An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a... |
Moderate |
firefox |
否 |
完成修复 |
2023-06-16 |
2026-01-24 |
| CVE-2023-35789 |
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be ente... |
Moderate |
librabbitmq |
是 |
完成修复 |
2023-06-16 |
2026-07-11 |
| CVE-2023-3268 |
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the r... |
Important |
kernel, kernel:4.18, kernel:6.6, kernel:4.19, kernel:5.10 |
是 |
完成修复 |
2023-06-16 |
2025-12-05 |
| CVE-2023-32067 |
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the ... |
Important |
nodejs:18, nodejs:16, c-ares |
否 |
完成修复 |
2023-06-16 |
2026-01-10 |
| CVE-2023-2431 |
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost ... |
Low |
kubernetes |
是 |
完成修复 |
2023-06-16 |
2026-03-25 |
| CVE-2023-3138 |
libX11中发现漏洞。出现安全漏洞的原因是libX11的src/InitExt.c中的函数不检查为请求、事件或错误ID�... |
Moderate |
libX11 |
是 |
完成修复 |
2023-06-15 |
2026-03-25 |
| CVE-2023-35116 |
DISPUTED jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a ... |
Moderate |
jackson-databind |
是 |
完成修复 |
2023-06-14 |
2026-07-09 |
| CVE-2023-2976 |
Use of Java's default temporary directory for file creation in FileBackedOutputStream in Google Guava versions 1.0 to 31.1 on... |
Moderate |
guava |
否 |
完成修复 |
2023-06-14 |
2026-01-22 |
| CVE-2023-26965 |
LibTIFF到4.5.0中的tools/tiffcrop.c中的loadImage()在释放后通过精心制作的TIFF图像进行基于堆的使用。 |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-14 |
2026-03-25 |
| CVE-2023-25434 |
libtiff4.5.0容易通过/libtiff/tools/tiffcrop.c:3215处的extractContigSamplesBytes()受到缓冲区溢出的影响。 |
Moderate |
libtiff |
是 |
完成修复 |
2023-06-14 |
2026-03-25 |
| CVE-2023-32032 |
.NET and Visual Studio Elevation of Privilege Vulnerability |
Important |
dotnet, dotnet7.0 |
否 |
完成修复 |
2023-06-13 |
2025-12-05 |
| CVE-2023-31439 |
DISPUTED An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file ... |
Moderate |
systemd |
是 |
完成修复 |
2023-06-13 |
2026-03-25 |
| CVE-2023-31438 |
DISPUTED An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing s... |
Moderate |
systemd |
是 |
完成修复 |
2023-06-13 |
2026-03-25 |
| CVE-2023-31437 |
DISPUTED An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not a... |
Moderate |
systemd |
是 |
完成修复 |
2023-06-13 |
2026-03-25 |