CVE List
| cve编号 | 漏洞描述 | 危险等级 | 包名 | 是否影响lns23-3 | 修复状态 | 发现时间 | 修复时间 |
|---|---|---|---|---|---|---|---|
| CVE-2022-43441 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A special... | Critical | sqlite | 否 | 完成修复 | 2023-03-16 | 2025-12-29 |
| CVE-2023-27539 | A denial of service vulnerability was found in rubygem-rack in how it parses headers. A carefully crafted input can cause heade... | Moderate | pcs, pcsc-lite-ccid | 是 | 完成修复 | 2023-03-15 | 2026-03-24 |
| CVE-2023-25345 | Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files vi... | Important | swig | 否 | 完成修复 | 2023-03-15 | 2026-01-04 |
| CVE-2023-25344 | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafte... | Critical | swig | 否 | 完成修复 | 2023-03-15 | 2026-01-07 |
| CVE-2023-1390 | A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link... | Moderate | kernel | 否 | 完成修复 | 2023-03-15 | 2026-01-04 |
| CVE-2023-1078 | Moderate | kernel | 否 | 完成修复 | 2023-03-15 | 2026-01-06 | |
| CVE-2023-1073 | Moderate | kernel | 否 | 完成修复 | 2023-03-15 | 2026-01-06 | |
| CVE-2023-28163 | A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue that when downloading files through t... | Moderate | firefox, thunderbird | 否 | 完成修复 | 2023-03-14 | 2026-01-24 |
| CVE-2023-1032 | No description is available for this CVE. | Moderate | kernel | 否 | 完成修复 | 2023-03-13 | 2026-01-06 |
| CVE-2023-0160 | No description is available for this CVE. | Low | kernel | 是 | 完成修复 | 2023-03-12 | 2026-01-22 |
| CVE-2023-1355 | A NULL pointer dereference vulnerability was discovered in vim's class_object_index() function at vim9class.c file. This flaw a... | Low | vim | 是 | 完成修复 | 2023-03-11 | 2026-03-24 |
| CVE-2023-23916 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compr... | Moderate | curl | 是 | 完成修复 | 2023-03-10 | 2026-03-24 |
| CVE-2023-1313 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | Important | cockpit | 否 | 完成修复 | 2023-03-10 | 2026-01-08 |
| CVE-2021-33360 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCalla... | Critical | gnuplot | 否 | 完成修复 | 2023-03-10 | 2026-01-10 |
| CVE-2023-27986 | A flaw was found in the Emacs text editor. A crafted mailto URI, when opened with emacsclient-mail.desktop, can result in Emacs... | Important | emacs | 否 | 完成修复 | 2023-03-08 | 2026-01-07 |
| CVE-2023-27985 | A flaw was found in the Emacs text editor. When opened with emacsclient-mail.desktop, a crafted mailto URI can result in shell ... | Important | emacs | 否 | 完成修复 | 2023-03-08 | 2026-01-07 |
| CVE-2023-27530 | A flaw was found in rubygem-rack. This issue occurs in the Multipart MIME parsing code in Rack, which limits the number of file... | Moderate | pcs | 是 | 完成修复 | 2023-03-08 | 2026-07-09 |
| CVE-2023-25690 | A vulnerability was found in httpd. This security issue occurs when some mod_proxy configurations on Apache HTTP Server allow a... | Important | httpd:2.4, httpd | 否 | 完成修复 | 2023-03-08 | 2026-01-09 |
| CVE-2023-24533 | Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can... | Important | golang | 是 | 完成修复 | 2023-03-08 | 2025-12-11 |
| CVE-2023-24532 | The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduc... | Moderate | golang | 是 | 完成修复 | 2023-03-08 | 2025-12-10 |
| CVE-2023-27522 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.... | Important | httpd:2.4, httpd | 否 | 完成修复 | 2023-03-07 | 2026-01-09 |
| CVE-2023-1476 | 此CVE没有可用的描述。 | Important | kernel | 是 | 完成修复 | 2023-03-07 | 2025-12-04 |
| CVE-2023-1264 | A NULL pointer dereference vulnerability was discovered in vim's utfc_ptr2len() function in the mbyte.c file. This issue is due... | Low | vim | 是 | 完成修复 | 2023-03-07 | 2026-07-09 |
| CVE-2022-4904 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which a... | Moderate | nodejs:18, nodejs:14, c-ares, nodejs:16 | 是 | 完成修复 | 2023-03-07 | 2026-03-24 |
| CVE-2022-40897 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a c... | Moderate | python27:2.7, python39:3.9, python-setuptools | 是 | 完成修复 | 2023-03-07 | 2026-03-24 |
| CVE-2022-40540 | A flaw was found in the Linux kernel. Memory corruption occurs to the buffer copy without checking the input size while loading... | Important | kernel | 否 | 完成修复 | 2023-03-06 | 2025-12-04 |
| CVE-2022-3854 | A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providi... | Moderate | ceph | 是 | 完成修复 | 2023-03-06 | 2026-07-13 |
| CVE-2021-20251 | A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being succ... | Moderate | samba | 是 | 完成修复 | 2023-03-06 | 2026-07-09 |
| CVE-2019-8720 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arb... | Moderate | gnome-settings-daemon | 是 | 完成修复 | 2023-03-06 | 2026-03-24 |
| CVE-2023-26604 | A vulnerability was found in the systemd package. The systemd package does not adequately block local privilege escalation for ... | Important | systemd | 否 | 完成修复 | 2023-03-04 | 2026-01-08 |
| CVE-2023-1175 | A flaw was found in Vim. There is an incorrect calculation of buffer size issue found in Vim's yank_copy_line() function of the... | Low | vim | 是 | 完成修复 | 2023-03-04 | 2026-07-09 |
| CVE-2023-1170 | A heap-based buffer overflow vulnerability was found in Vim's utf_ptr2char() function of the src/mbyte.c file. This flaw occurs... | Low | vim | 是 | 完成修复 | 2023-03-04 | 2026-07-09 |
| CVE-2023-1161 | A flaw was found in the ISO 15765 and ISO 10681 dissectors of Wireshark. This issue occurs when decoding malformed packets from... | Moderate | wireshark | 否 | 完成修复 | 2023-03-04 | 2026-01-25 |
| CVE-2022-41862 | A flaw was found In PostgreSQL. A modified, unauthenticated server can send an unterminated string during the establishment of ... | Low | postgresql-jdbc, libpq, postgresql:13, postgresql:12 | 是 | 完成修复 | 2023-03-04 | 2026-03-24 |
| CVE-2023-1118 | Moderate | kernel | 否 | 完成修复 | 2023-03-03 | 2026-01-06 | |
| CVE-2023-25155 | A vulnerability was found in Redis. This flaw allows authenticated users issuing specially crafted SRANDMEMBER, ZRANDMEMBER, an... | Moderate | redis, redis:6 | 是 | 完成修复 | 2023-03-02 | 2026-03-24 |
| CVE-2023-23006 | In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uar... | Moderate | kernel | 否 | 完成修复 | 2023-03-02 | 2026-01-04 |
| CVE-2023-23004 | Low | kernel, kernel(ANCK)5.10 | 否 | 完成修复 | 2023-03-02 | 2026-01-22 | |
| CVE-2023-23002 | In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (ex... | Moderate | kernel | 否 | 完成修复 | 2023-03-02 | 2026-01-04 |
| CVE-2023-23000 | Low | kernel | 否 | 完成修复 | 2023-03-02 | 2026-01-22 | |
| CVE-2023-22462 | A flaw was found in the Grafana core plugin, "Text." The vulnerability was possible due to React's render cycle that will pass ... | Moderate | grafana | 否 | 完成修复 | 2023-03-02 | 2026-01-25 |
| CVE-2023-1160 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. | Moderate | cockpit | 是 | 完成修复 | 2023-03-02 | 2026-07-13 |
| CVE-2023-1077 | Moderate | kernel | 否 | 完成修复 | 2023-03-02 | 2026-01-04 | |
| CVE-2023-1076 | Low | kernel | 是 | 完成修复 | 2023-03-02 | 2026-01-22 | |
| CVE-2022-36021 | A vulnerability was found in Redis. This flaw allows an authenticated to use string matching commands (like SCAN or KEYS) with ... | Moderate | redis, redis:6 | 是 | 完成修复 | 2023-03-02 | 2026-03-24 |
| CVE-2023-23003 | In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value. | Moderate | kernel | 否 | 完成修复 | 2023-03-01 | 2026-01-04 |
| CVE-2023-23001 | In the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to ... | Moderate | kernel | 否 | 完成修复 | 2023-03-01 | 2026-01-04 |
| CVE-2023-22998 | In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return v... | Moderate | kernel:4.19, kernel:6.6, kernel, kernel:5.10 | 否 | 完成修复 | 2023-03-01 | 2026-01-04 |
| CVE-2023-1127 | A flaw was found in Vim. A division by zero in the scrolldown function may lead to a denial of service, modified memory, and po... | Low | vim | 是 | 完成修复 | 2023-03-01 | 2026-03-24 |
| CVE-2023-1075 | Low | kernel | 是 | 完成修复 | 2023-03-01 | 2026-01-22 | |
| CVE-2023-1074 | Low | kernel | 是 | 完成修复 | 2023-03-01 | 2026-01-22 | |
| CVE-2023-1018 | An out-of-bound read vulnerability was found in the TPM 2.0's Module Library, which allows the reading of 2-byte data after the... | Moderate | libtpms, virt:an | 是 | 完成修复 | 2023-03-01 | 2026-07-11 |
| CVE-2023-0594 | A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide ... | Important | grafana | 否 | 完成修复 | 2023-03-01 | 2026-01-04 |
| CVE-2022-4645 | A flaw was found in tiffcp, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-b... | Moderate | libtiff, compat-libtiff3 | 是 | 完成修复 | 2023-03-01 | 2026-07-11 |
| CVE-2022-41725 | A flaw was found in Go, where it is vulnerable to a denial of service caused by an excessive resource consumption flaw in the n... | Moderate | container-tools:4.0, grafana, weldr-client, container-tools:3.0, container-tools:an8, osbuild-composer, git-lfs, golang, grafana-pcp | 是 | 完成修复 | 2023-03-01 | 2025-12-10 |
| CVE-2022-41724 | A flaw was found in Golang Go, where it is vulnerable to a denial of service caused when processing large TLS handshake records... | Moderate | container-tools:4.0, grafana, weldr-client, container-tools:3.0, container-tools:an8, osbuild-composer, git-lfs, golang, grafana-pcp | 是 | 完成修复 | 2023-03-01 | 2025-12-10 |
| CVE-2022-3294 | Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted u... | Moderate | kubernetes | 是 | 完成修复 | 2023-03-01 | 2026-03-24 |
| CVE-2022-3162 | Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different ... | Moderate | kubernetes | 是 | 完成修复 | 2023-03-01 | 2026-03-24 |
| CVE-2023-27371 | An out-of-bounds flaw was found in GNU's libmicrohttpd due to improper parsing of a multipart/form-data boundary in the MHD_cre... | Moderate | libmicrohttpd | 否 | 完成修复 | 2023-02-28 | 2026-01-25 |
| CVE-2023-27320 | A double-free vulnerability was found in Sudo in the per-command chroot feature. This flaw exists due to a boundary error when ... | Moderate | sudo | 否 | 完成修复 | 2023-02-28 | 2026-01-25 |
| CVE-2023-23518 | A vulnerability was found in WebKitGTK. This issue occurs when processing maliciously crafted web content in WebKit. A remote a... | Important | webkitgtk, webkit2gtk3 | 否 | 完成修复 | 2023-02-28 | 2026-01-04 |
| CVE-2023-23517 | A vulnerability was found in WebKitGTK. This issue occurs when processing maliciously crafted web content in WebKit. This may a... | Important | webkitgtk, webkit2gtk3 | 否 | 完成修复 | 2023-02-28 | 2026-01-04 |
| CVE-2023-22999 | In the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev return value... | Low | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-22 |
| CVE-2023-22997 | In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to... | Low | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-22 |
| CVE-2023-22996 | In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use,... | Low | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-21 |
| CVE-2023-22995 | Low | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-21 | |
| CVE-2023-20938 | In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This cou... | Important | kernel | 是 | 完成修复 | 2023-02-28 | 2025-12-04 |
| CVE-2023-1095 | In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. ... | Moderate | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-04 |
| CVE-2023-1017 | An out-of-bounds write vulnerability was found in the TPM 2.0's Module Library, which allows the writing of 2-byte data after t... | Moderate | libtpms | 是 | 完成修复 | 2023-02-28 | 2026-07-11 |
| CVE-2023-0461 | There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To re... | Moderate | kernel | 否 | 完成修复 | 2023-02-28 | 2026-01-04 |
| CVE-2022-42826 | A vulnerability was found in WebKitGTK. This issue exists due to a use-after-free error when processing maliciously crafted web... | Important | webkitgtk, webkit2gtk3 | 否 | 完成修复 | 2023-02-28 | 2026-01-04 |
| CVE-2022-41727 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. Thi... | Moderate | golang-x-image | 是 | 完成修复 | 2023-02-28 | 2025-12-10 |
| CVE-2023-1544 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to all... | Low | qemu-kvm-ma, virt:an, qemu-kvm | 否 | 完成修复 | 2023-02-27 | 2025-12-18 |
| CVE-2023-1055 | A flaw was found in RHDS 11 and 12. While browsing entries, LDAP tries to decode the userPassword attribute instead of the user... | Moderate | 389-ds-base, 389-ds:1.4 | 是 | 完成修复 | 2023-02-27 | 2026-07-13 |
| CVE-2022-32891 | The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a web... | Moderate | webkitgtk, webkit2gtk3 | 是 | 完成修复 | 2023-02-27 | 2026-07-11 |
| CVE-2023-26607 | In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | Moderate | kernel | 否 | 完成修复 | 2023-02-26 | 2026-01-04 |
| CVE-2023-26606 | In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c. | Moderate | kernel | 否 | 完成修复 | 2023-02-26 | 2026-01-04 |
| CVE-2023-26605 | In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del... | Moderate | kernel | 否 | 完成修复 | 2023-02-26 | 2026-01-04 |
| CVE-2023-26545 | Moderate | kernel | 否 | 完成修复 | 2023-02-25 | 2026-01-04 | |
| CVE-2023-26544 | In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sect... | Moderate | kernel 4.19, kernel 5.10 | 否 | 完成修复 | 2023-02-25 | 2026-01-04 |
| CVE-2023-23920 | An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacke... | Low | nodejs:16, nodejs:18, nodejs:14, nodejs-packaging, nodejs | 是 | 完成修复 | 2023-02-24 | 2026-03-24 |
| CVE-2023-23919 | A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the... | Moderate | nodejs:18, nodejs, nodejs:16, nodejs-packaging | 是 | 完成修复 | 2023-02-24 | 2026-03-24 |
| CVE-2023-23918 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass... | Moderate | nodejs:16, nodejs:18, nodejs:14, nodejs-packaging, nodejs | 是 | 完成修复 | 2023-02-24 | 2026-03-24 |
| CVE-2023-23529 | A vulnerability was found in WebKitGTK. This issue occurs when processing maliciously crafted web content in WebKit. This may, ... | Important | webkit2gtk3 | 否 | 完成修复 | 2023-02-24 | 2026-01-04 |
| CVE-2022-4203 | A flaw was found in Open SSL. A read buffer overrun can be triggered in X.509 certificate verification, specifically in name co... | Moderate | openssl | 否 | 完成修复 | 2023-02-24 | 2026-01-25 |
| CVE-2022-38023 | Netlogon RPC Elevation of Privilege Vulnerability. | Important | samba | 否 | 完成修复 | 2023-02-24 | 2026-01-09 |
| CVE-2023-25746 | Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that wi... | Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25744 | Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and w... | Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25743 | A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome. *... |
Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25742 | The Mozilla Foundation Security Advisory describes this flaw as: | Moderate | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2026-01-24 |
| CVE-2023-25739 | Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <c... | Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25737 | An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnera... |
Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25735 | Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main... | Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25732 | The Mozilla Foundation Security Advisory describes this flaw as: | Moderate | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2026-01-24 |
| CVE-2023-25730 | A background script invoking requestFullscreen and then blocking the main thread could force the browser into full... |
Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-25729 | The Mozilla Foundation Security Advisory describes this flaw as: | Moderate | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2026-01-24 |
| CVE-2023-25728 | The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI whe... |
Important | firefox, thunderbird | 否 | 完成修复 | 2023-02-22 | 2025-12-30 |
| CVE-2023-23039 | A race condition leading to a use-after-free vulnerability was found in the Linux kernel's Sun Virtual Console Concentrator (VC... | Moderate | kernel | 否 | 完成修复 | 2023-02-22 | 2026-01-04 |
| CVE-2023-23009 | A flaw was found in the Libreswan package. A crafted TS payload with an incorrect selector length may allow a remote attacker t... | Moderate | libreswan | 是 | 完成修复 | 2023-02-22 | 2026-03-27 |
| CVE-2023-0767 | The Mozilla Foundation Security Advisory describes this flaw as: | Important | firefox, nss, thunderbird | 否 | 完成修复 | 2023-02-22 | 2026-01-07 |