| | | | | | |
| Vmware Spring Framework 代码问题漏洞 | | | | | |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-4cwg-f7qc-6r95 |
| | | | | | https://issues.apache.org/jira/browse/XMLBEANS-517 |
| | | | | | https://github.com/scipy/scipy/pull/15013 |
| Terracotta Quartz Scheduler 代码注入漏洞 | | | | | https://github.com/quartz-scheduler/quartz/issues/943 |
| | | | | | https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt |
| | | | | | https://curl.se/docs/CVE-2024-11053.html |
| | | | | | https://github.com/apache/xerces-c/pull/54 |
| | | | | | https://github.com/requirejs/r.js |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://struts.apache.org/core-developers/file-upload |
| | | | | | https://lists.apache.org/thread/b2b9qrgjrz1kvo4ym8y2wkfdvwoq6qbp |
| | | | | | https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc@%3Cdev.creadur.apache.org%3E |
| | | | | | https://github.com/libssh2/libssh2/pull/476 |
| | | | | | https://github.com/scikit-learn/scikit-learn/issues/18891 |
| | | | | | https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb |
| | | | | | https://docs.gradle.org/7.0/release-notes.html#security-advisori |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-6j2p-252f-7mw8 |
| | | | | | https://github.com/hunterhacker/jdom。 |
| Intel OneApi Toolkits 代码问题漏洞 | | | | | http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00674.html |
| | | | | | https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw |
| | | | | | https://github.com/jettison-json/jettison/issues/45 |
| Apache Commons FileUpload 安全漏洞 | | | | | https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy |
| | | | | | https://lists.apache.org/thread/q9qpdlv952gb4kphpndd5phvl7fkh71r |
| | | | | | https://github.com/google/guava |
| | | | | | |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-84mw-qh6q-v842 |
| Microsoft ODBC Driver 安全漏洞 | | | | | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36730 |
| Microsoft ODBC Driver 安全漏洞 | | | | | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36785 |
| | | | | | https://nodejs.org/en/blog/vulnerability/october-2023-security-releases |
| | | | | | https://lists.apache.org/thread/q142wj99cwdd0jo5lvdoxzoymlqyjdds |
| | | | | | https://bugzilla.samba.org/show_bug.cgi?id=15439 |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f |
| | | | | | https://kb.isc.org/docs/cve-2023-4408 |
| | | | | | https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q |
| HashiCorp Terraform 路径遍历漏洞 | | | | | https://discuss.hashicorp.com/t/hcsec-2023-27-terraform-allows-arbitrary-file-write-during-init-operation/58082 |
| | | | | | https://github.com/grpc/grpc/releases/tag/v1.58.1 |
| | | | | | https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1 |
| | | | | | https://bitbucket.org/b_c/jose4j/downloads/ |
| | | | | | https://www.jfree.org/jfreechart/ |
| Connect2id Nimbus JOSE+JWT 安全漏洞 | | | | | https://connect2id.com/products/nimbus-jose-jwt |
| | | | | | https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b |
| | | | | | https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/12 |
| | | | | | https://github.com/gentoo/cpython/commit/a6a90cac7e1af91b032dcf0df13437857bc6c112 |
| | | | | | https://github.com/benoitc/gunicorn |
| | | | | | https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-cve-2024-22019---high |
| | | | | | https://spring.io/security/cve-2024-22262 |
| | | | | | https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f |
| | | | | | https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg |
| | | | | | https://go-review.googlesource.com/c/protobuf/+/569356 |
| | | | | | https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce |
| | | | | | https://github.com/dnsjava/dnsjava/security/advisories/GHSA-cfxw-4h78-h7fw |
| | | | | | https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55 |
| | | | | | https://lists.apache.org/thread/6536rmzyg076lzzdw2xdktvnz163mjpy |
| | | | | | https://nodejs.org/en/blog/vulnerability/april-2024-security-releases |
| | | | | | https://github.com/libexpat/libexpat/pull/842 |
| Apache Commons Configuration 缓冲区错误漏洞 | | | | | https://lists.apache.org/thread/03nzzzjn4oknyw5y0871tw7ltj0t3r37 |
| Apache Commons Configuration 缓冲区错误漏洞 | | | | | https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31680 |
| | | | | | https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l |
| RADIUS Protocol under RFC 2865 安全漏洞 | | | | | https://www.rfc-editor.org/ |
| | | | | | https://github.com/airlift/aircompressor/releases/tag/0.27 |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62 |
| VMware Spring Framework 安全漏洞 | | | | | https://spring.io/security/cve-2024-38816 |
| VMware Spring Framework 安全漏洞 | | | | | https://docs.spring.io/spring-framework/reference/web/webmvc.html |
| | | | | | https://github.com/python/cpython/commit/8ed546679524140d8282175411fd141fe7df070d |
| | | | | | https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.1-36 |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://lists.apache.org/thread/3f3oph7bqnqspb9q5p0gm5mgc1b6thjo |
| | | | | | https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674 |
| | | | | | https://x-stream.github.io/CVE-2024-47072.html |
| | | | | | https://github.com/openssl/openssl |
| Apache Commons IO 资源管理错误漏洞 | | | | | https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1 |
| | | | | | https://github.com/pallets/werkzeug/releases/tag/3.0 |
| | | | | | https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r |
| Red Hat Undertow 资源管理错误漏洞 | | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2293069 |
| | | | | | |
| | | | | | https://github.com/jeremyhylton/cpython/commit/1587608515127032778669c8232d46ec6d8f593c |
| Red Hat Undertow 竞争条件问题漏洞 | | | | | |
| | | | | | https://github.com/php/php-src/security/advisories/GHSA-94p6-54jq-9mwp |
| | | | | | https://github.com/gradle/gradle/pull/8927 |
| | | | | | https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e@<announce.apache.org> |
| | | | | | https://github.com/gradle/gradle/pull/10543 |
| | | | | | |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-89qm-pxvm-p336 |
| | | | | | https://github.com/memcached/memcached/pull/806/commits/264722ae4e248b453be00e97197dadc685b60fd0 |
| | | | | | https://github.com/golang/go/issues/58003 |
| | | | | | https://github.com/scipy/scipy/issues/16235 |
| | | | | | |
| | | | | | https://pkg.go.dev/vuln/GO-2023-1990 |
| | | | | | https://pkg.go.dev/vuln/GO-2023-1989 |
| | | | | | https://github.com/grpc/grpc/pull/32309 |
| | | | | | https://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bcc |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-2h6c-rv6q-494v |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://www.samba.org/samba/security/CVE-2023-3961.html |
| | | | | | https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-mrff-q8qj-xvg8 |
| | | | | | https://www.samba.org/samba/security/CVE-2023-42669.html |
| | | | | | https://github.com/gradle/gradle/security/advisories/GHSA-43r3-pqhv-f7h9 |
| Apache Santuario 日志信息泄露漏洞 | | | | | https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55 |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4 |
| | | | | | https://curl.se/docs/CVE-2023-46218.html |
| | | | | | https://curl.se/docs/CVE-2023-46219.html |
| | | | | | https://www.openssh.com/openbsd.html |
| Apache Portable Runtime 安全漏洞 | | | | | https://lists.apache.org/thread/sntjc04t1rvjhdzz2tzmtz2zdnmv7dc4 |
| | | | | | https://cryptography.io/en/latest/ |
| | | | | | https://github.com/json-path/JsonPath/issues/973 |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017 |
| | | | | | https://gitlab.com/gnutls/gnutls/-/commit/29d6298d0b04cfff970b993915db71ba3f580b6d |
| | | | | | https://www.openssl.org/news/secadv/20240109.txt |
| | | | | | https://github.com/the-tcpdump-group/libpcap/commit/262e4f34979872d822ccedf9f318ed89c4d31c03 |
| | | | | | https://sqlite.org/forum/forumpost/4aa381993a |
| | | | | | https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85 |
| | | | | | https://grafana.com/grafana/download/10.3.4 |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://github.com/pallets/jinja/releases/tag/3.1.3 |
| | | | | | https://github.com/nahsra/antisamy/releases/tag/v1.7.5 |
| | | | | | |
| | | | | | |
| | | | | | https://go.dev/issue/67555 |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/ch5yo2d21p7vlqrhll9b17otbyq4npfg |
| | | | | The Ruby Programming Language | https://rubygems.org/gems/stringio/versions/3.0 |
| | | | | The Ruby Programming Language | https://rubygems.org/gems/rdoc/versions/6.3.4.1 |
| | | | | | https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/ |
| | | | | | https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.ht |
| | | | | | https://gnutls.org/download.html |
| | | | | | https://gitlab.com/gnutls/gnutls/-/commit/4a4cefef6c194f8fbbffd7fb19651219421b085b |
| | | | | | https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp |
| | | | | | https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c |
| | | | | | https://github.com/expressjs/express/releases/tag/v5.0.0-beta |
| | | | | | https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004 |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31678 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31679 |
| | | | | | https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://github.com/psf/requests/releases/tag/v2.32 |
| | | | | | https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-34jh-p97f-mpxf |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://spring.io/security/cve-2024-38807 |
| VMware Spring Framework 安全漏洞 | | | | | https://spring.io/security/cve-2024-38809 |
| VMware Spring Security 安全漏洞 | | | | | https://spring.io/security/cve-2024-38827 |
| | | | | | https://github.com/requirejs/r.js |
| | | | | | https://github.com/python/cpython/commit/895f7e2ac23eff4743143beef0f0c5ac71ea27d3 |
| Apache HTTP Server 代码问题漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://github.com/snowflakedb/snowflake-jdbc/security/advisories/GHSA-f686-hw9c-xw9c |
| | | | | | https://github.com/netty/netty/releases/tag/netty-4.1.115.Final |
| | | | | | https://lists.apache.org/thread/c2v7mhqnmq0jmbwxqq3r5jbj1xg43h5x |
| | | | | | https://www.jenkins.io/security/advisory/2024-10-02/#SECURITY-3451 |
| | | | | | https://www.jenkins.io/security/advisory/2024-10-02/#SECURITY-3448 |
| | | | | | https://github.com/pallets/werkzeug/releases/tag/3.0 |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://lists.apache.org/thread/lopzlqh91jj9n334g02om08sbysdb928 |
| | | | | | https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n |
| | | | | | https://openssl-library.org/news/secadv/20240903.txt |
| | | | | | https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf |
| | | | | | https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh |
| | | | | | https://github.com/python/cpython |
| | | | | | https://github.com/the-tcpdump-group/libpcap/commit/8a633ee5b9ecd9d38a587ac9b204e2380713b0d6 |
| | | | | | https://mail.python.org/archives/list/security-announce@python.org/thread/GNFCKVI4TCATKQLALJ5SN4L4CSPSMILU/ |
| | | | | | https://curl.se/docs/CVE-2024-8096.html |
| | | | | | https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2 |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| VMware Spring Framework 安全漏洞 | | | | | https://spring.io/security/cve-2024-38820 |
| | | | | | https://www.openssl.org/news/secadv/20240516.txt |
| | | | | | https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87 |
| | | | | | https://openssl-library.org/news/secadv/20241016.txt |