序号 | | | | | | |
| Terracotta Quartz Scheduler 代码问题漏洞 | | | | | http://www.quartz-scheduler.org/ |
| Dell BSAFE Micro Edition Suite和Dell BSAFE 输入验证错误漏洞 | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427 |
| | | | | | https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427 |
| Apache DB DdlUtils 代码问题漏洞 | | | | | https://lists.apache.org/thread.html/r3d7a8303a820144f5e2d1fd0b067e18d419421b58346b53b58d3fa72%40%3Cannounce.apache.org%3E |
| | | | | | https://github.com/itext/itext7/releases/tag/7.1.17 |
| | | | | | https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2 |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability |
| | | | | The HSQL Development Group | https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50212#c7 |
| Apache Commons Text 代码注入漏洞 | | | | | https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om |
| Apache Commons BCEL 缓冲区错误漏洞 | | | | | https://lists.apache.org/thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4 |
| | | | | | https://lists.apache.org/thread/g4l64s283njhnph2otx7q4gs2j952d31 |
| | | | | | https://lists.apache.org/thread/q23kvvtoohgzwybxpwozmvvk17rp0td3 |
| | | | | | https://lists.apache.org/thread/pdzo1qgyplf4y523tnnzrcm7hoco3l8c |
| VMware Spring Security 安全漏洞 | | | | | https://spring.io/security/cve-2023-34034 |
| | | | | | https://github.com/curl/curl/commit/fb4415d8aee6c1 |
| | | | | | https://support.apple.com/en-us/HT213930 |
| | | | | | https://www.npmjs.com/package/ip |
| | | | | | https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b |
| | | | | | https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt |
| | | | | | https://github.com/Perl/perl5/commit/ff1f9f59360afeebd6f75ca1502f5c3ebf077da3 |
| PostgreSQL JDBC Driver 安全漏洞 | | | | | https://github.com/pgjdbc/pgjdbc/releases/tag/REL42.7.2 |
| | | | | | http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019 |
| jackson-mapper-asl 代码问题漏洞 | | | | | https://mvnrepository.com/artifact/org.codehaus.jackson |
| Red Hat Hibernate ORM SQL注入漏洞 | | | | | |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities |
| | | | | | https://bugs.python.org/issue43223 |
| | | | | | https://access.redhat.com/security/cve/cve-2021-36770 |
| | | | | | https://github.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8 |
| | | | | | https://github.com/sparklemotion/nekohtml/commit/a800fce3b079def130ed42a408ff1d09f89e773d |
| | | | | | https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-h4h5-3hr4-j3g2 |
| | | | | | https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw |
| | | | | | https://github.com/x-stream/xstream/issues/304 |
| Apache XML Graphics Batik 代码问题漏洞 | | | | | https://lists.apache.org/thread/hplhx0o74jb7blj39fm4kw3otcnjd6xf |
| FasterXML jackson-databind 代码问题漏洞 | | | | | https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33 |
| FasterXML jackson-databind 代码问题漏洞 | | | | | https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88 |
| Apache XML Graphics Batik 代码问题漏洞 | | | | | https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly |
| Apache XML Graphics Batik 代码问题漏洞 | | | | | https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2 |
| | | | | | https://github.com/dromara/hutool/issues/2748 |
| | | | | | https://lists.apache.org/thread/1dj60hg5nr36kjr4p1100dwjrqookps8 |
| | | | | | https://github.com/pmachapman/unrar/commit/2ecab6bb5ac4f3b88f270218445496662020205f#diff-ca3086f578522062d7e390ed2cd7e10f646378a8b8cbf287a6e4db5966df68ee |
| | | | | | https://www.openssl.org/news/secadv/20230322.txt |
| Red Hat JBoss Enterprise Application Platform 安全漏洞 | | | | | https://github.com/ICEPAY/REST-API-NET/commit/61f6b8758e5c971abff5f901cfa9f231052b775f |
| | | | | | https://netplex.github.io/json-smart/ |
| | | | | | https://research.jfrog.com/vulnerabilities/jettison-json-array-dos-xray-427911/ |
| | | | | | https://spring.io/security/cve-2023-20860 |
| | | | | | https://github.com/SpiderLabs/ModSecurity/pull/2857/commits/4324f0ac59f8225aa44bc5034df60dbeccd1d334 |
| Apache Commons FileUpload 安全漏洞 | | | | | https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy |
| | | | | | https://github.com/opencv/opencv_contrib/pull/3480 |
| | | | | | https://github.com/opencv/opencv_contrib/pull/3484/commits/2b62ff6181163eea029ed1cab11363b4996e9cd6 |
| Intel oneAPI Toolkits 代码问题漏洞 | | | | | http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html |
| | | | | | https://gitlab.gnome.org/GNOME/glib/ |
| | | | | | https://github.com/google/guava |
| Apache HTTP Server 缓冲区错误漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | |
| | | | | | https://gitlab.gnome.org/GNOME/glib/ |
| | | | | | https://gitlab.gnome.org/GNOME/glib/ |
| | | | | | https://github.com/spring-projects/spring-framework/releases/tag/v6.0. |
| | | | | | https://lists.apache.org/thread/j1ksjh9m9gx1q60rtk1sbzmxhvj5h5qz |
| | | | | | https://www.jenkins.io/security/advisory/2023-06-14/#SECURITY-3135 |
| | | | | | https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b |
| | | | | | https://github.com/eclipse/jetty.project/security/advisories/GHSA-wgh7-54f2-x98r |
| | | | | | https://docs.python.org/3/library/email.html |
| HCL BigFix Platform 输入验证错误漏洞 | | | | | https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0107791 |
| | | | | | https://github.com/curl/curl |
| python-cryptography 信任管理问题漏洞 | | | | | https://github.com/pyca/cryptography/issues/9207 |
| | | | | | https://github.com/krb5/krb5/commit/88a1701b423c13991a8064feeb26952d3641d840 |
| | | | | | https://github.com/eclipse-ee4j/parsson/commit/9dd5ad5f871f7b93654073a3f8ce3e1d9b8d9b31 |
| | | | | | https://github.com/redis/redis/commit/e351099e1119fb89496be578f5232c61ce300224 |
| | | | | | https://support.apple.com/en-us/HT213938 |
| | | | | | https://github.com/python/cpython/pull/107982 |
| | | | | | https://support.apple.com/en-us/HT214033 |
| | | | | | https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3072 |
| | | | | | https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3073 |
| | | | | | https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3073 |
| Apache HTTP Server 资源管理错误漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f |
| | | | | | https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7 |
| | | | | | https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q |
| OpenTelemetry-Go Contrib 安全漏洞 | | | | | https://github.com/open-telemetry/opentelemetry-go-contrib/security/advisories/GHSA-5r5m-65gx-7vrh |
| | | | | | https://github.com/plotly/plotly.js/releases/tag/v2.25.2 |
| | | | | | https://github.com/shadow-maint/shadow/commit/65c88a43a23c2391dcc90c0abda3e839e9c57904 |
| | | | | | https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr |
| | | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2249523 |
| | | | | | |
| | | | | | https://www.openssl.org/news/secadv/20230908.txt |
| | | | | | https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html |
| | | | | | https://www.gnu.org/software/libc/ |
| | | | | | https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressions |
| | | | | | https://solr.apache.org/security.html#cve-2023-50386-apache-solr-backuprestore-apis-allow-for-deployment-of-executables-in-malicious-configsets |
| | | | | | https://github.com/stleary/JSON-java/ |
| | | | | | https://github.com/jasper-software/jasper/commit/aeef5293c978158255ad4f127089644745602f2a |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=30884 |
| | | | | | https://bitbucket.org/b_c/jose4j/downloads/ |
| Connect2id Nimbus JOSE+JWT 安全漏洞 | | | | | https://connect2id.com/products/nimbus-jose-jwt |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0df40630850fb2740e6be6890bb905d3fc623b2d |
| | | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2242099 |
| | | | | | https://github.com/kraj/glibc/releases/tag/glibc-2.37 |
| | | | | | https://logback.qos.ch/download.html |
| Quality Open Software Logback 安全漏洞 | | | | | https://logback.qos.ch/news.html |
| | | | | | https://github.com/kraj/glibc/releases/tag/glibc-2.38 |
| Red Hat Undertow 资源管理错误漏洞 | | | | | |
| | | | | | https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv |
| | | | | | https://github.com/amazon-ion/ion-java/security/advisories/GHSA-264p-99wq-f4j6 |
| | | | | | https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#code-injection-and-privilege-escalation-through-linux-capabilities-cve-2024-21892---high |
| | | | | | https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-cve-2024-22019---high |
| | | | | | https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98 |
| | | | | | https://spring.io/security/cve-2024-22233/ |
| | | | | | https://spring.io/projects/spring-framework#support |
| VMware Spring Security 安全漏洞 | | | | | https://spring.io/security/cve-2024-22257 |
| | | | | | https://spring.io/security/cve-2024-22259 |
| | | | | | https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f |
| | | | | | https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg |
| | | | | | https://gitlab.gnome.org/GNOME/libxml2/-/tags |
| | | | | | https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55 |
| | | | | | |
| | | | | | |
| Apache Commons Net 输入验证错误漏洞 | | | | | https://lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7 |
| JetBrains Kotlin 安全特征问题漏洞 | | | | | http://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021 |
| | | | | | https://cxsecurity.com/cveshow/CVE-2022-24613/ |
| | | | | | https://cxsecurity.com/cveshow/CVE-2022-24614/ |
| Apache Portable Runtime 输入验证错误漏洞 | | | | | https://lists.apache.org/thread/np5gjqlohc4f62lr09vrn61vl44cylh8 |
| | | | | | https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9 |
| | | | | | https://github.com/jhy/jsoup/security/advisories/GHSA-gp7f-rwcx-9369 |
| Matthäus G. Chajdas pygments 代码问题漏洞 | | | | | https://pypi.org/project/Pygments/ |
| | | | | | https://www.openssl.org/news/secadv/20230328.txt |
| | | | | | https://www.openssl.org/news/secadv/20230328.txt |
| | | | | | https://www.redhat.com/en/resources/amq-streams-datasheet |
| | | | | | https://www.openssl.org/news/vulnerabilities.html#CVE-2023-1255 |
| | | | | | https://spring.io/security/cve-2023-20861 |
| | | | | | https://spring.io/security/cve-2023-20862 |
| | | | | | https://spring.io/security/cve-2023-20863 |
| | | | | | https://www.debian.org/security/2023/ |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a |
| Intel oneAPI Toolkits 安全漏洞 | | | | | http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html |
| | | | | | https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67 |
| Flexera InstallShield 安全漏洞 | | | | | https://community.flexera.com/t5/Product-Downloads/ct-p/Downloads |
| | | | | | https://www.openssl.org/news/secadv/20230714.txt |
| | | | | | https://gitlab.gnome.org/GNOME/glib/ |
| | | | | | https://gitlab.gnome.org/GNOME/glib/ |
| | | | | | https://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bcc |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://spring.io/security/cve-2023-34035 |
| | | | | | https://github.com/spring-projects/spring-boot/releases/tag/v3.0. |
| | | | | | https://www.openssl.org/news/secadv/20230719.txt |
| FasterXML jackson-databind 代码问题漏洞 | | | | | https://github.com/FasterXML/jackson-databind/issues/3972 |
| | | | | | https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2 |
| | | | | | https://github.com/eclipse/jetty.project/security/advisories/GHSA-3gh6-v5v9-6v9j |
| | | | | | https://www.openssl.org/news/secadv/20230731.txt |
| | | | | | https://www.jenkins.io/security/advisory/2023-07-26/#SECURITY-3188 |
| | | | | | https://gitlab.com/procps-ng/procps |
| | | | | | https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6 |
| | | | | | https://www.python.org/dev/security/ |
| | | | | | https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f |
| | | | | | https://github.com/eclipse/jetty.project/security/advisories/GHSA-pwh8-58vv-vw48 |
| Apache Commons Compress 资源管理错误漏洞 | | | | | https://lists.apache.org/thread/5xwcyr600mn074vgxq92tjssrchmc93c |
| | | | | | https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3261 |
| | | | | | https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3245 |
| Apache Santuario 日志信息泄露漏洞 | | | | | https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=30842 |
| Apache HTTP Server 资源管理错误漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4 |
| | | | | | https://curl.se/docs/CVE-2023-46218.html |
| | | | | | https://curl.se/docs/CVE-2023-46219.html |
| | | | | | |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=30843 |
| | | | | | https://www.openssh.com/openbsd.html |
| Python cryptography 代码问题漏洞 | | | | | https://github.com/pyca/cryptography/security/advisories/GHSA-jfhm-5ghh-2f97 |
| | | | | | https://cryptography.io/en/latest/ |
| | | | | | https://github.com/json-path/JsonPath/issues/973 |
| | | | | | https://github.com/ImageMagick/ImageMagick/commit/aa673b2e4defc7cad5bec16c4fc8324f71e531f1 |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017 |
| | | | | | https://www.openssl.org/news/secadv/20240109.txt |
| | | | | | https://mail.python.org/archives/list/[email protected]/thread/AUL7QFHBLILGISS7U63B47AYSSGJJQZD/ |
| | | | | | https://github.com/kraj/glibc/releases/tag/glibc-2.38 |
| | | | | | https://curl.se/docs/CVE-2024-0853.html |
| | | | | | https://undertow.io/downloads.html |
| | | | | | https://github.com/pallets/jinja/releases/tag/3.1.3 |
| | | | | | https://github.com/nahsra/antisamy/releases/tag/v1.7.5 |
| | | | | | https://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cb |
| | | | | | https://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cb |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/ch5yo2d21p7vlqrhll9b17otbyq4npfg |
| | | | | | https://github.com/google/guava/issues/4011 |
| | | | | | https://github.com/curl/curl/releases |
| | | | | Python Packaging Authority | https://github.com/pypa/pip/releases/tag/23.3.1 |
| | | | | | https://www.libssh.org/files/0.10/ |
| | | | | | https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ |
| | | | | | https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2 |