CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-29400 Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output wit... Important golang, golang-dbus, container-tools:an8, container-tools:3.0, go-toolset:an8, grafana 完成修复 2023-05-11 2025-12-10
CVE-2023-2664 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow. Moderate xpdf, poppler 完成修复 2023-05-11 2026-03-24
CVE-2023-2663 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. Moderate Xpdf, poppler 完成修复 2023-05-11 2026-03-24
CVE-2023-2662 In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero. Moderate xpdf, poppler 完成修复 2023-05-11 2026-03-24
CVE-2023-24539 Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple acti... Important golang, container-tools:2.0, golang-dbus, container-tools:an8, container-tools:3.0, container-tools:4.0, grafana 完成修复 2023-05-11 2025-12-10
CVE-2023-28410 Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before... Moderate kernel 完成修复 2023-05-10 2026-01-06
CVE-2023-25568 Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.... Important golang 完成修复 2023-05-10 2025-12-11
CVE-2023-2483 In emac_probe, &adpt->work_thread is bound with emac_work_thread. Then it will be started by timeout handler emac_tx_timeout or... Moderate kernel 完成修复 2023-05-10 2026-01-06
CVE-2023-2430 A vulnerability due to missing lock on overflow for IOPOLL bug in io_cqring_event_overflow() in io_uring.c in Linux kernel thro... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2023-05-10 2026-01-06
CVE-2023-1193 The use-after-free in setup_async_work() \n \nMissing check for syncrhonous state and make ksmbd_work object not be dequeued fr... Moderate kernel 5.10, kernel 4.19 完成修复 2023-05-10 2026-01-06
CVE-2022-43507 Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potent... Important qatengine 完成修复 2023-05-10 2026-01-04
CVE-2022-41808 Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated... Moderate kernel:5.10, kernel:4.19, kernel 完成修复 2023-05-10 2026-01-06
CVE-2023-32570 VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_f... Moderate dav1d 完成修复 2023-05-09 2026-01-22
CVE-2023-32233 In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perf... Moderate kernel 完成修复 2023-05-09 2026-01-06
CVE-2023-31975 yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Low yasm 完成修复 2023-05-09 2026-06-24
CVE-2023-30086 Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp func... Moderate libtiff 完成修复 2023-05-09 2026-03-24
CVE-2023-29104 A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC7... Moderate libbpf 完成修复 2023-05-09 2026-03-24
CVE-2023-2610 Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532. Important vim 完成修复 2023-05-09 2026-01-05
CVE-2023-2609 NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. Important vim 完成修复 2023-05-09 2026-01-05
CVE-2023-24932 Secure Boot Security Feature Bypass Vulnerability Moderate shim 完成修复 2023-05-09 2026-07-09
CVE-2023-2156 A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results fr... Moderate kernel 完成修复 2023-05-09 2026-01-06
CVE-2023-32214 协议处理程序ms-cxh和ms-cxh-full可能被用来触发拒绝服务。注意:此攻击仅影响Windows。其他操作系�... Moderate firefox, thunderbird, firefox_esr 完成修复 2023-05-08 2026-01-24
CVE-2023-27954 The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iP... Moderate webkit2gtk3 完成修复 2023-05-08 2026-07-12
CVE-2023-27932 This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and i... Moderate webkit2gtk3 完成修复 2023-05-08 2026-07-12
CVE-2023-2513 A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for e... Moderate kernel 完成修复 2023-05-08 2026-01-06
CVE-2022-32885 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monter... Moderate webkit2gtk3 完成修复 2023-05-08 2026-07-12
CVE-2023-31047 In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form f... Moderate python-django 完成修复 2023-05-07 2026-03-24
CVE-2023-32269 An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept ... Moderate kernel 完成修复 2023-05-05 2026-01-06
CVE-2023-29942 llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMV... Moderate mesa-private-llvm, llvm 完成修复 2023-05-05 2025-12-05
CVE-2023-29941 llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::spars... Moderate llvm 完成修复 2023-05-05 2025-12-05
CVE-2023-29939 llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv... Moderate llvm 完成修复 2023-05-05 2025-12-05
CVE-2023-29935 llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was alread... Moderate llvm 完成修复 2023-05-05 2025-12-05
CVE-2023-29934 llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect(). Moderate llvm 完成修复 2023-05-05 2025-12-05
CVE-2023-29932 llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand. Moderate llvm 完成修复 2023-05-05 2025-12-05
CVE-2022-20566 In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalatio... Important kernel:5.10, kernel:4.19, kernel, kernel:6.6 完成修复 2023-05-05 2025-12-05
CVE-2023-30570 A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received... Important libreswan 完成修复 2023-05-03 2026-01-05
CVE-2022-43681 An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that end... Moderate frr 完成修复 2023-05-03 2026-07-10
CVE-2022-40318 An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Ext... Moderate frr 完成修复 2023-05-03 2026-07-10
CVE-2022-40302 An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Ext... Moderate frr 完成修复 2023-05-03 2026-07-10
CVE-2023-2236 A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. ... Important kernel 5.10, kernel 4.19 完成修复 2023-05-01 2025-12-05
CVE-2023-2426 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. Low vim 完成修复 2023-04-29 2026-03-24
CVE-2023-31436 qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed... Moderate kernel 完成修复 2023-04-28 2026-01-06
CVE-2022-4662 A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local u... Moderate kernel:5.10, kernel:4.19, kernel, kernel:6.6 完成修复 2023-04-28 2026-01-06
CVE-2022-41849 drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physic... Moderate kernel 完成修复 2023-04-28 2026-01-06
CVE-2023-28882 Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because s... Moderate mod_security 完成修复 2023-04-27 2026-07-10
CVE-2023-25652 Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.3... Important git 完成修复 2023-04-26 2026-01-06
CVE-2023-1786 Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find has... Moderate cloud-init 完成修复 2023-04-26 2026-01-22
CVE-2023-1387 Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the a... Moderate grafana 完成修复 2023-04-26 2026-01-22
CVE-2023-0458 A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value ... Moderate kernel 完成修复 2023-04-26 2026-01-06
CVE-2023-29012 Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted... Important git 完成修复 2023-04-25 2026-01-06
CVE-2023-29011 Git for Windows, the Windows port of Git, ships with an executable called connect.exe, which implements a SOCKS5 proxy that c... Important git 完成修复 2023-04-25 2026-01-06
CVE-2023-2269 A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in ... Moderate kernel:4.19, kernel:4.18, kernel:6.6, kernel, kernel:5.10 完成修复 2023-04-25 2026-01-06
CVE-2023-31085 An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->er... Moderate kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-31083 An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condit... Moderate kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-31082 An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid con... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-29469 在2.10.4之前的libxml2中发现了一个问题。当对精心设计的XML文档中的空dict字符串进行哈希处理时�... Moderate libxml2 完成修复 2023-04-24 2026-01-22
CVE-2023-28484 在2.10.4之前的libxml2中,解析某些无效的XSD模式可能会导致NULL指针取消引用,进而导致段错误。�... Moderate libxml2 完成修复 2023-04-24 2026-01-22
CVE-2023-2019 A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the im... Moderate kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-2007 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performin... Moderate kernel:6.6, kernel:4.19, kernel:5.10, kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-2006 A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue res... Moderate kernel 完成修复 2023-04-24 2026-01-06
CVE-2023-31084 An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a ... Moderate kernel 完成修复 2023-04-23 2026-01-06
CVE-2023-1998 The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables ... Moderate kernel 完成修复 2023-04-21 2026-01-06
CVE-2023-2194 An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" ... Moderate kernel 完成修复 2023-04-20 2026-01-06
CVE-2023-2177 A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_i... Moderate kernel 完成修复 2023-04-20 2026-01-06
CVE-2023-2176 A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper c... Important kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-04-20 2025-12-05
CVE-2023-1255 Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM\nplatform contains a bug that could cause it to read... Low openssl 完成修复 2023-04-20 2026-01-22
CVE-2023-2166 A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may not be in... Moderate kernel 完成修复 2023-04-19 2026-01-06
CVE-2023-2162 A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in th... Moderate kernel 完成修复 2023-04-19 2026-01-06
CVE-2022-2084 Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. Thi... Moderate cloud-init 完成修复 2023-04-19 2026-01-22
CVE-2023-28856 Redis is an open source, in-memory database that persists on disk. Authenticated users can use the HINCRBYFLOAT command to cr... Moderate redis, redis:6 完成修复 2023-04-18 2026-03-24
CVE-2023-26049 Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cooki... Moderate jetty 完成修复 2023-04-18 2026-07-09
CVE-2023-26048 Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with ... Moderate jetty 完成修复 2023-04-18 2026-07-09
CVE-2023-21980 Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected a... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21977 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21966 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are ... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21962 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that ar... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21947 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that ar... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21940 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that ar... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21935 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21933 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21919 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-21913 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2023-04-18 2026-03-24
CVE-2023-30772 The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a p... Moderate kernel 完成修复 2023-04-16 2026-01-06
CVE-2023-24607 Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHA... Important qt5-qtbase 完成修复 2023-04-15 2026-01-04
CVE-2021-43612 In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds hea... Moderate lldpd 完成修复 2023-04-15 2026-07-11
CVE-2023-29383 In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Alth... Moderate util-linux 完成修复 2023-04-14 2026-03-24
CVE-2023-2008 A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue result... Important kernel 完成修复 2023-04-14 2025-12-05
CVE-2023-30630 Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of... Important dmidecode 完成修复 2023-04-13 2026-01-06
CVE-2023-29491 ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corrupti... Important ncurses 完成修复 2023-04-13 2026-01-10
CVE-2022-48468 protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. Moderate protobuf-c 完成修复 2023-04-13 2026-01-22
CVE-2023-1994 GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted ... Moderate wireshark 完成修复 2023-04-12 2026-01-22
CVE-2023-1993 LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or craf... Moderate wireshark 完成修复 2023-04-12 2026-01-22
CVE-2023-1992 RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or craft... Important wireshark 完成修复 2023-04-12 2026-01-05
CVE-2023-1990 A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attac... Moderate kernel 完成修复 2023-04-12 2026-01-22
CVE-2023-1872 A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation. \n ... Important kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-04-12 2025-12-05
CVE-2023-28260 .NET DLL Hijacking Remote Code Execution Vulnerability Important dotnet 完成修复 2023-04-11 2025-12-05
CVE-2023-25950 HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a ... Important haproxy 完成修复 2023-04-11 2026-01-05
CVE-2023-1989 A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to b... Moderate kernel 完成修复 2023-04-11 2026-01-06
CVE-2023-1829 tcindex里的uaf漏洞,需要开启CAP_NET_ADMIN权限才能触发,影响版本2.6.12-rc2<=版本<6.3-rc1包含4.19和5.10 Important kernel 完成修复 2023-04-11 2025-12-05
CVE-2022-43548 A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient Is... Important nodejs:18, nodejs, nodejs:14, nodejs:16 完成修复 2023-04-11 2026-01-05

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""