CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-0616 If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display ... Moderate thunderbird 完成修复 2023-02-22 2026-06-26
CVE-2022-20369 In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could le... Moderate kernel 完成修复 2023-02-22 2026-01-04
CVE-2023-26253 A flaw was found in Gluster, where GlusterFS is vulnerable to a denial of service caused by a stack-based buffer over-read flaw... Moderate glusterfs 完成修复 2023-02-21 2026-06-24
CVE-2022-48340 A flaw was found in Gluster, where GlusterFS is vulnerable to a denial of service caused by an xlators/cluster/dht/src/dht-comm... Important glusterfs 完成修复 2023-02-21 2025-12-29
CVE-2022-48339 A flaw was found in the Emacs package. If a file name or directory name contains shell metacharacters, arbitrary code may be ex... Important emacs 完成修复 2023-02-21 2026-01-07
CVE-2022-48338 A flaw was found in the Emacs package. A malicious ruby source file may cause a local command injection. Moderate emacs 完成修复 2023-02-21 2026-07-12
CVE-2022-48337 A flaw was found in the Emacs package. This flaw allows attackers to execute commands via shell metacharacters in the name of a... Moderate emacs-php-mode, emacs, emacs-auctex 完成修复 2023-02-21 2026-07-12
CVE-2021-32857 Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2... Moderate cockpit 完成修复 2023-02-21 2026-07-13
CVE-2023-27561 A flaw was found in runc. An attacker who controls the container image for two containers that share a volume can race volume m... Moderate container-tools:4.0, container-tools:2.0, runc, container-tools:3.0, container-tools:an8, container-tools:1.0 完成修复 2023-02-20 2026-07-13
CVE-2023-26242 afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow. Moderate kernel:6.6, kernel:4.19, kernel:5.10 完成修复 2023-02-20 2026-01-17
CVE-2023-24998 Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of... Moderate tomcat 完成修复 2023-02-20 2026-06-26
CVE-2022-32231 A flaw was found in hw. Improper initialization in the BIOS firmware for some Intel(R) processors may allow a privileged user t... Important kernel 完成修复 2023-02-20 2025-12-04
CVE-2022-30704 A flaw was found in hw. Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) processors may allow a privileg... Moderate kernel 完成修复 2023-02-20 2026-01-04
CVE-2022-30539 A flaw was found in how. Use-after-free in the BIOS firmware for some Intel(R) processors may allow a privileged user to potent... Important kernel 完成修复 2023-02-20 2025-12-04
CVE-2022-26837 A flaw was found in hw. Improper input validation in the BIOS firmware for some Intel(R) processors may allow a privileged user... Important kernel 完成修复 2023-02-20 2025-12-04
CVE-2022-26343 A flaw was found in hw. Improper access control in the BIOS firmware for some Intel(R) processors may allow a privileged user t... Important kernel 完成修复 2023-02-20 2025-12-04
CVE-2021-0187 A flaw was found in hw. Improper access control in the BIOS firmware for some Intel(R) processors may allow a privileged user t... Low kernel 完成修复 2023-02-20 2026-01-22
CVE-2023-24807 Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the Headers.set() and Headers.append() methods are vulne... Low nodejs:16, nodejs:18, nodejs:20, nodejs-packaging, nodejs 完成修复 2023-02-17 2026-03-24
CVE-2023-24329 A flaw was found in the Python package. An issue in the urllib.parse component could allow attackers to bypass blocklisting met... Important python2, python3, python38:3.8, python39:3.9, python, python27:2.7 完成修复 2023-02-17 2026-01-09
CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not ... Moderate nodejs, nodejs:16, nodejs:18, nodejs-packaging 完成修复 2023-02-17 2026-03-24
CVE-2023-23586 A use-after-free vulnerability was discovered in the Linux kernel's io_uring subsystem. It was found that it is possible to ins... Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-02-17 2026-01-04
CVE-2023-22795 ActionDispatch<6.1.7.1和<7.0.4.1中存在与If-None-Match标头相关的基于正则表达式的DoS漏洞。当Ruby版本低�... Moderate ruby 完成修复 2023-02-17 2026-07-09
CVE-2022-41723 A flaw was found in golang. A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, suf... Moderate container-tools:4.0, grafana, golang-dbus, go-toolset:an8, rhc-worker-playbook, docker, container-tools:3.0, container-tools:an8, osbuild-composer, git-lfs, rhc, golang, grafana-pcp 完成修复 2023-02-17 2025-12-10
CVE-2022-36369 A potential flaw was found in QATzip. This vulnerability may allow escalation of privileges. Important qatzip 完成修复 2023-02-17 2026-01-04
CVE-2021-33391 An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in ... Critical kernel 完成修复 2023-02-17 2025-12-04
CVE-2021-32142 A flaw was found in the LibRaw package. A stack buffer overflow in the LibRawbuffer_datastream::gets() function in src/libraw... Moderate LibRaw 完成修复 2023-02-17 2026-07-11
CVE-2022-38090 A flaw was found in the Linux kernel. A potential security vulnerability in some Intel Processors with Intel Software Guard Ext... Moderate microcode_ctl 完成修复 2023-02-16 2026-07-10
CVE-2022-36397 Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow a... Important kernel 完成修复 2023-02-16 2025-12-04
CVE-2022-33196 A flaw was found in the Linux kernel. Some Intel(R) Xeon(R) processors with Intel? Software Guard Extensions (SGX) may allow pr... Important microcode_ctl 完成修复 2023-02-16 2026-01-05
CVE-2022-26841 Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an authent... Moderate kernel 完成修复 2023-02-16 2026-01-04
CVE-2022-21216 A flaw was found in the Linux kernel. A potential security vulnerability in some Intel(R) Atom(R) and Intel(R) Xeon(R) Scalable... Moderate microcode_ctl 完成修复 2023-02-16 2026-07-10
CVE-2021-43529 Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME mes... Critical thunderbird 完成修复 2023-02-16 2026-01-07
CVE-2023-25761 Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting... Moderate junit 完成修复 2023-02-15 2026-07-09
CVE-2023-25173 A flaw was found in containerd, where supplementary groups are not set up properly inside a container. If an attacker has direc... Moderate container-tools:4.0, buildah, container-tools:2.0, conmon, podman, container-tools:3.0, skopeo, container-tools:an8, container-tools:1.0, containerd 完成修复 2023-02-15 2026-03-24
CVE-2023-23946 A vulnerability was found in Git. This security issue occurs when feeding a crafted input to "git apply." A path outside the wo... Moderate git 完成修复 2023-02-15 2026-03-24
CVE-2023-23915 A flaw was found in the Curl package, where the HSTS mechanism could fail when multiple transfers are done in parallel, as the ... Low curl 完成修复 2023-02-15 2026-03-24
CVE-2023-23914 A flaw was found in the Curl package, where the HSTS mechanism would be ignored by subsequent transfers when done on the same c... Low curl 完成修复 2023-02-15 2026-03-24
CVE-2023-22490 A vulnerability was found in Git. Using a specially-crafted repository, Git can be tricked into using its local clone optimizat... Moderate git 完成修复 2023-02-15 2026-03-24
CVE-2023-0662 A vulnerability was found in PHP. This security flaw occurs when the request body parsing in PHP allows any unauthenticated att... Moderate php, php:7.4, php:8.0 完成修复 2023-02-15 2026-07-10
CVE-2023-0568 A vulnerability was found in PHP. This security issue occurs because the core path resolution function allocates a buffer one b... Moderate php:7.4, php:8.0, php 完成修复 2023-02-15 2026-07-10
CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blow... Low php:7.4, php:8.0, php 完成修复 2023-02-15 2026-07-10
CVE-2023-25745 The Mozilla Foundation Security Advisory: Mozilla developers Timothy Nikkel, Gabriele Svelto, Jeff Muizelaar, and the Mozilla F... Important firefox 完成修复 2023-02-14 2026-01-04
CVE-2023-25741 The Mozilla Foundation Security Advisory: When dragging and dropping an image cross-origin, the image size could potentially be... Low firefox 完成修复 2023-02-14 2026-01-24
CVE-2023-25740 The Mozilla Foundation Security Advisory: After downloading a Windows .scf script from the local filesystem, an attacker coul... Moderate firefox 完成修复 2023-02-14 2026-01-24
CVE-2023-25738 The Mozilla Foundation Security Advisory describes this flaw as: \n \nMembers of the DEVMODEW struct set by the printer devic... Important firefox, thunderbird 完成修复 2023-02-14 2025-12-30
CVE-2023-25736 The Mozilla Foundation Security Advisory: An invalid downcast from nsHTMLDocument to nsIContent could lead to undefined beh... Low firefox 完成修复 2023-02-14 2026-01-24
CVE-2023-25734 The Mozilla Foundation Security Advisory describes this flaw as: After downloading a Windows .url shortcut from the local ... Moderate firefox, thunderbird 完成修复 2023-02-14 2026-01-24
CVE-2023-25733 The Mozilla Foundation Security Advisory: The return value from gfx::SourceSurfaceSkia::Map() wasn't being verified, which co... Low firefox 完成修复 2023-02-14 2026-01-24
CVE-2023-25731 The Mozilla Foundation Security Advisory: Due to URL previews in the network panel of developer tools improperly storing URLs, ... Low firefox 完成修复 2023-02-14 2026-01-24
CVE-2023-25725 A flaw was found in HAProxy's headers processing that causes HAProxy to drop important headers fields such as Connection, Conte... Moderate haproxy 完成修复 2023-02-14 2026-01-25
CVE-2023-25577 A flaw was found in python-werkzeug. Werkzeug is multipart form data parser, that will parse an unlimited number of parts, incl... Important python-werkzeug 完成修复 2023-02-14 2026-01-04
CVE-2023-21808 A vulnerability exists in how dotnet reads debugging symbols. Reading a malicious symbols file may result in remote code execut... Important dotnet6.0, dotnet3.1, dotnet7.0 完成修复 2023-02-14 2025-12-05
CVE-2023-0361 A timing side-channel vulnerability was found in RSA ClientKeyExchange messages in GnuTLS. This side-channel may be sufficient ... Moderate gnutls 完成修复 2023-02-14 2026-07-10
CVE-2022-27672 A flaw was found in HW. When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from ... Moderate kernel 完成修复 2023-02-14 2026-01-04
CVE-2012-6088 A flaw was found in rpm. The rpmpkgRead function in lib/package.c in the RPM package does not return an error code in certain s... Moderate rpm 完成修复 2023-02-13 2026-01-25
CVE-2023-0804 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0803 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0802 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0801 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0800 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0799 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to a use-aft... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0798 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0797 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0796 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2023-0795 A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of... Moderate libtiff, compat-libtiff3 完成修复 2023-02-12 2026-03-24
CVE-2022-0987 在PackageKit中,Transaction接口公开的一些方法检查文件的方式中发现了一个缺陷。此问题允许本地�... Low PackageKit 完成修复 2023-02-12 2026-07-10
CVE-2022-43552 A vulnerability was found in curl. In this issue, curl can be asked to tunnel all protocols virtually it supports through an HT... Low curl 完成修复 2023-02-10 2026-03-24
CVE-2023-0759 Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. Moderate cockpit 完成修复 2023-02-09 2026-07-13
CVE-2023-0401 A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the h... Important openssl-pkcs11, openssl 完成修复 2023-02-09 2026-01-09
CVE-2023-0286 There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were ... Important compat-openssl10, ovmf, openssl, edk2 完成修复 2023-02-09 2026-01-07
CVE-2023-0217 An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EV... Important openssl-pkcs11, openssl, nodejs:20, OVMF, nodejs 完成修复 2023-02-09 2026-01-09
CVE-2023-0216 A flaw was found in OpenSSL. An invalid pointer dereference on read can be triggered when an application tries to load malforme... Important openssl-pkcs11, nodejs:10, edk2, openssl, nodejs:16, nodejs:12, nodejs:18, nodejs:20, nodejs:14, OVMF, nodejs 完成修复 2023-02-09 2026-01-09
CVE-2023-0215 The public API function BIO_new_NDEF is a helper function used for streaming \nASN.1 data via a BIO. It is primarily used inter... Important nodejs:10, edk2, openssl, nodejs:16, nodejs:12, nodejs:18, openssl1.1, nodejs:14, nodejs:20, OVMF, nodejs 完成修复 2023-02-09 2025-12-29
CVE-2022-4450 The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and \ndecodes the "name" (e.g. "CERTIFICATE"), any header... Important openssl, edk2, OVMF, openssl1.1 完成修复 2023-02-09 2026-01-09
CVE-2022-4304 Moderate openssl, edk2 完成修复 2023-02-09 2026-03-27
CVE-2023-23931 A vulnerability was found in python-cryptography. In affected versions, Cipher.update_into would accept Python objects which ... Moderate python-cryptography, python39:3.9 完成修复 2023-02-08 2026-06-24
CVE-2022-46663 A vulnerability was found in less. This flaw allows crafted data to result in "less -R" not filtering ANSI escape sequences sen... Important less 完成修复 2023-02-08 2026-01-09
CVE-2022-45142 The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" com... Important samba 完成修复 2023-02-08 2026-01-09
CVE-2023-0687 A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __mo... Low glibc, glibc32 完成修复 2023-02-07 2025-12-11
CVE-2023-0494 A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2023-02-07 2026-01-04
CVE-2023-0430 The Mozilla Foundation Security Advisory describes this flaw as: Important thunderbird 完成修复 2023-02-07 2026-01-04
CVE-2023-25193 A vulnerability was found HarfBuzz. This flaw allows attackers to trigger O(n^2) growth via consecutive marks during the proces... Moderate java-17-openjdk, harfbuzz, thunderbird, java-11-openjdk, firefox 完成修复 2023-02-04 2025-12-05
CVE-2022-36109 Moby是Docker创建的一个开源项目,旨在实现软件容器化。Moby(Docker引擎)中发现了一个错误,其�... Moderate docker, moby 完成修复 2023-02-04 2026-03-24
CVE-2023-25139 sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer ... Moderate glibc 完成修复 2023-02-03 2025-12-11
CVE-2023-25136 A flaw was found in the OpenSSH server (sshd), which introduced a double-free vulnerability during options.kex_algorithms handl... Moderate openssh 完成修复 2023-02-03 2026-07-09
CVE-2023-21843 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound). Supported ... Low java-11-openjdk, java-1.8.0-openjdk 完成修复 2023-02-03 2025-12-05
CVE-2023-21835 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported v... Moderate java-11-openjdk 完成修复 2023-02-03 2025-12-05
CVE-2023-21830 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Su... Moderate java-1.8.0-openjdk 完成修复 2023-02-03 2025-12-05
CVE-2023-0045 No description is available for this CVE. Moderate kernel:4.19, kernel:6.6, kernel, kernel:5.10 完成修复 2023-02-03 2025-12-30
CVE-2022-3560 A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit ru... Important pesign 完成修复 2023-02-03 2026-01-04
CVE-2022-23498 A flaw was found in the Grafana package. When data-source query caching is enabled, Grafana caches all headers, including `graf... Important grafana 完成修复 2023-02-03 2026-01-04
CVE-2021-37519 A flaw was found in memcached, where it is vulnerable to a denial of service caused by a heap-based buffer overflow in the auth... Low memcached 完成修复 2023-02-03 2026-03-24
CVE-2023-25012 The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device bec... Moderate kernel 4.19, kernel(ANCK)5.10 完成修复 2023-02-02 2025-12-30
CVE-2023-0615 A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code fun... Moderate kernel 完成修复 2023-02-02 2026-01-22
CVE-2023-0597 A memory leak flaw has been found in the Linux Kernel. Moderate kernel 完成修复 2023-02-01 2026-01-04
CVE-2023-0590 A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This flaw lead... Moderate kernel 完成修复 2023-02-01 2026-01-04
CVE-2022-25147 A flaw was found in Apache Portable Runtime (APR). This issue may allow a malicious attacker to write beyond the bounds of a bu... Moderate apr-util 完成修复 2023-02-01 2026-03-27
CVE-2022-46344 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2023-01-31 2026-01-04
CVE-2022-46343 A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may ... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2023-01-31 2026-01-04
CVE-2022-46342 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may wri... Important xorg-x11-server-Xwayland, xorg-x11-server, tigervnc 完成修复 2023-01-31 2026-01-04

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""