检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XM9M-2VJ8-FMFR CVE-2021-28029 | Uninitialized memory access in toodee | 高危 | crates.iotoodee | 已审查 | 2021-09-02 02:30 | 2021-08-31 05:56 |
| GHSA-WCVP-R8J8-47PC CVE-2021-28028 | Double free in toodee |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 严重 |
crates.iotoodee |
| 已审查 |
| 2021-09-02 02:30 |
| 2023-06-14 05:58 |
| GHSA-V92M-HHHW-VV9V CVE-2019-19208 | Code injection in codiad | 严重 | Packagistcodiad/codiad | 已审查 | 2021-09-02 02:27 | 2021-08-31 05:59 |
| GHSA-Q4RF-3FHX-88PF CVE-2021-39132 | YAML deserialization can run untrusted code | 中危 | Mavenorg.rundeck:rundeck-core | 已审查 | 2021-09-02 02:27 | 2021-08-31 06:03 |
| GHSA-3JMW-C69H-426C CVE-2021-39133 | Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server | 高危 | Mavenorg.rundeck:rundeck-core | 已审查 | 2021-09-02 02:26 | 2021-08-31 06:03 |
| GHSA-JJ53-8FMW-F2W2 CVE-2021-39163 | Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner. | 低危 | PyPImatrix-synapse | 已审查 | 2021-09-02 02:25 | 2024-09-24 23:37 |
| GHSA-3X4C-PQ33-4W3Q CVE-2021-39164 | Improper authorisation of members discloses room membership to non-members | 低危 | PyPImatrix-synapse | 已审查 | 2021-09-02 02:25 | 2024-09-24 23:36 |
| GHSA-5RWJ-J5M3-3CHJ CVE-2021-39176 | Missing Release of Memory after Effective Lifetime in detect-character-encoding | 高危 | npmdetect-character-encoding | 已审查 | 2021-09-02 02:25 | 2021-10-21 22:28 |
| GHSA-9GR3-7897-PP7M CVE-2021-39178 | XSS in Image Optimization API for Next.js | 高危 | npmnext | 已审查 | 2021-09-02 02:24 | 2021-09-01 04:01 |
| GHSA-VWHC-PWW7-72X6 CVE-2021-32831 | Code Injection in total.js | 高危 | npmtotal.js | 已审查 | 2021-09-02 02:24 | 2021-09-01 04:25 |
| GHSA-RPQ8-MMWH-Q9HM CVE-2020-6950 | Directory traversal in Eclipse Mojarra | 高危 | Mavenorg.glassfish:mojarra-parent | 已审查 | 2021-09-02 02:23 | 2022-02-09 05:23 |
| GHSA-CPH5-M8F7-6C5X CVE-2021-3749 | axios Inefficient Regular Expression Complexity vulnerability | 高危 | npmaxios | 已审查 | 2021-09-02 02:23 | 2022-09-15 05:28 |
| GHSA-HW4V-5X4H-C3XM CVE-2021-39193 | Transaction validity oversight in pallet-ethereum | 中危 | crates.iopallet-ethereum | 已审查 | 2021-09-02 02:22 | 2024-10-25 05:18 |
| GHSA-W6J8-JC36-X5Q9 CVE-2021-39166 | Improper Neutralization of Text-Values in Object Version Preview | 高危 | Packagistpimcore/pimcore | 已审查 | 2021-09-02 02:22 | 2021-09-02 02:19 |
| GHSA-2V88-QQ7X-XQ5F CVE-2021-39170 | Improper Encoding or Escaping of Output in Asset Metadata Component | 高危 | Packagistpimcore/pimcore | 已审查 | 2021-09-02 02:21 | 2021-09-02 02:20 |
| GHSA-9R2W-394V-53QC CVE-2021-37701 | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links | 高危 | npmtar | 已审查 | 2021-09-01 00:05 | 2021-09-01 00:01 |
| GHSA-QQ89-HQ3F-393P CVE-2021-37712 | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links | 高危 | npmtar | 已审查 | 2021-09-01 00:05 | 2021-09-01 00:02 |
| GHSA-5955-9WPR-37JH CVE-2021-37713 | Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization | 高危 | npmtar | 已审查 | 2021-09-01 00:05 | 2021-09-01 00:02 |
| GHSA-2H3H-Q99F-3FHC CVE-2021-39134 | @npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following | 高危 | npm@npmcli/arborist | 已审查 | 2021-09-01 00:04 | 2022-08-16 04:08 |
| GHSA-GMW6-94GG-2RC2 CVE-2021-39135 | UNIX Symbolic Link (Symlink) Following in @npmcli/arborist | 高危 | npm@npmcli/arborist | 已审查 | 2021-09-01 00:03 | 2022-06-18 04:51 |
| GHSA-34JQ-548X-M2X9 CVE-2021-38623 | Improper Resource Shutdown or Release in TYPO3 extension | 高危 | Packagistwebcoast/deferred-image-processing | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:19 |
| GHSA-23FQ-Q7HC-993R CVE-2021-38553 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 | 严重 | Gogithub.com/hashicorp/vault | 已审查 | 2021-08-31 01:22 | 2022-08-12 05:57 |
| GHSA-6239-28C2-9MRM CVE-2021-38554 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault | 中危 | Gogithub.com/hashicorp/vault | 已审查 | 2021-08-31 01:22 | 2022-08-04 19:22 |
| GHSA-JJ8R-P9F5-FMVV CVE-2021-36785 | Cross-site Scripting in TYPO3 extension | 中危 | Packagistminiorange/miniorange-saml | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:07 |
| GHSA-H5Q8-5697-9P9H CVE-2020-22403 | Cross-Site Request Forgery in express-cart | 高危 | npmexpress-cart | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:02 |