| | | | | | |
| | | | | | https://lists.apache.org/thread.html/r50d389c613ba6062a26aa57e163c09bfee4ff2d95d67331d75265b83@%3Cannounce.apache.org%3E |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2 |
| | | | | | https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2 |
| | | | | | https://www.openssl.org/source/ |
| | | | | | https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y |
| | | | | | https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability |
| Apache HTTP Server 环境问题漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://github.com/XKCP/XKCP/commit/fdc6fef075f4e81d6b1bc38364248975e08e340a |
| | | | | | https://lists.apache.org/thread/q23kvvtoohgzwybxpwozmvvk17rp0td3 |
| | | | | | https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 |
| | | | | | https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8 |
| | | | | | https://github.com/curl/curl/commit/fb4415d8aee6c1 |
| | | | | | https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b |
| | | | | | https://github.com/madler/zlib/pull/843 |
| | | | | | https://github.com/python-pillow/Pillow/releases/tag/10.2 |
| | | | | | https://www.openssh.com/txt/release-9.6 |
| | | | | | https://www.php.net/downloads.php |
| | | | | | https://github.com/requirejs/r.js |
| | | | | | https://www.jenkins.io/security/advisory/2024-08-07/#SECURITY-3430 |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://www.php.net/downloads |
| jackson-mapper-asl 代码问题漏洞 | | | | | https://mvnrepository.com/artifact/org.codehaus.jackson |
| | | | | | |
| | | | | | https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504 |
| | | | | | https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv |
| | | | | | https://github.com/netty/netty/security/advisories/GHSA-9vjp-v76f-g363 |
| | | | | | https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w |
| | | | | | https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh |
| | | | | | https://access.redhat.com/security/cve/cve-2022-2601 |
| | | | | | https://github.com/moment/moment/pull/6015#issuecomment-1152961973 |
| | | | | | https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw |
| Intel(R) oneAPI DPC++/C++ Compiler 代码问题漏洞 | | | | | https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00773.html |
| | | | | | https://github.com/openssl/openssl/ |
| Intel(R) oneAPI DPC++/C++ Compiler 安全漏洞 | | | | | https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00773.html |
| Intel oneAPI DPC++/C++ Compiler 缓冲区错误漏洞 | | | | | https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00773.html |
| | | | | | https://github.com/python/cpython/issues/97514 |
| | | | | | https://www.openssl.org/news/secadv/20230207.txt |
| | | | | | https://python-security.readthedocs.io/vuln/slow-idna-large-strings.html |
| | | | | | https://ubuntu.com/security/notices/USN-5845-1 |
| | | | | | https://ubuntu.com/security/notices/USN-5844-1 |
| | | | | | https://ubuntu.com/security/notices/USN-5844-1 |
| | | | | | https://ubuntu.com/security/notices/USN-5845-1 |
| | | | | | https://ubuntu.com/security/notices/USN-5844-1 |
| | | | | | https://lists.apache.org/thread/q9qpdlv952gb4kphpndd5phvl7fkh71r |
| | | | | | https://lists.apache.org/thread/wkx6grrcjkh86crr49p4blc1v1nflj3t |
| Intel oneAPI Toolkits 代码问题漏洞 | | | | | http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html |
| | | | | | https://www.openldap.org/software/download/ |
| | | | | | https://github.com/google/guava |
| | | | | | https://github.com/xerial/snappy-java/security/advisories/GHSA-pqr6-cmr2-h8hf |
| | | | | | https://github.com/xerial/snappy-java/security/advisories/GHSA-fjpj-2g6w-x25r |
| | | | | | https://github.com/xerial/snappy-java/security/advisories/GHSA-qcwq-55hx-v3vh |
| | | | | | https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b |
| | | | | | https://lists.apache.org/thread/q142wj99cwdd0jo5lvdoxzoymlqyjdds |
| | | | | | https://github.com/eclipse-ee4j/parsson/commit/9dd5ad5f871f7b93654073a3f8ce3e1d9b8d9b31 |
| | | | | | https://support.apple.com/en-us/HT214035 |
| | | | | | https://github.com/xerial/snappy-java/security/advisories/GHSA-55g7-9cwv-5qfv |
| | | | | | https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q |
| | | | | | https://pkg.go.dev/vuln/GO-2024-2687 |
| | | | | | https://github.com/pallets/werkzeug/security/advisories/GHSA-hrfv-mqp8-q5rw |
| | | | | | https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/11 |
| | | | | | https://www.openssl.org/news/secadv/20230908.txt |
| | | | | | https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html |
| | | | | | https://github.com/stleary/JSON-java/ |
| | | | | | https://bitbucket.org/b_c/jose4j/downloads/ |
| | | | | | https://github.com/libexpat/libexpat/pull/789 |
| Connect2id Nimbus JOSE+JWT 安全漏洞 | | | | | https://connect2id.com/products/nimbus-jose-jwt |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0df40630850fb2740e6be6890bb905d3fc623b2d |
| | | | | | https://github.com/xnio/xnio/tags |
| | | | | | https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b |
| | | | | | https://gitlab.freedesktop.org/xorg/xserver/-/tags/xorg-server-21.1.11 |
| | | | | | https://gitlab.freedesktop.org/xorg/xserver/-/tags/xorg-server-21.1.11 |
| | | | | | https://www.x.org/wiki/XServer/ |
| | | | | | https://www.x.org/wiki/XServer/ |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98 |
| VMware Spring Security 安全漏洞 | | | | | https://spring.io/security/cve-2024-22257 |
| | | | | | https://spring.io/security/cve-2024-22262 |
| | | | | | https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f |
| | | | | | https://github.com/apache/xerces-c/pull/54 |
| | | | | | https://curl.se/docs/CVE-2024-2398.html |
| | | | | | https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg |
| | | | | | https://my.f5.com/manage/s/article/K000138444 |
| | | | | | https://my.f5.com/manage/s/article/K000138445 |
| | | | | | https://gitlab.gnome.org/GNOME/libxml2/-/tags |
| | | | | | https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce |
| | | | | | https://github.com/strukturag/libheif/pull/1074 |
| | | | | | https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55 |
| | | | | | https://nodejs.org/en/blog/vulnerability/april-2024-security-releases |
| Apache Commons Configuration 缓冲区错误漏洞 | | | | | https://lists.apache.org/thread/03nzzzjn4oknyw5y0871tw7ltj0t3r37 |
| Apache Commons Configuration 缓冲区错误漏洞 | | | | | https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 |
| | | | | | https://www.bouncycastle.org/latest_releases.html |
| | | | | | https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 |
| | | | | | https://www.x.org/wiki/Development/Documentation/SubmittingPatches/ |
| | | | | | https://www.x.org/wiki/Development/Documentation/SubmittingPatches/ |
| | | | | | https://lists.apache.org/thread/stwrgsr1llb73nkl16klv9vjqgmmx633 |
| | | | | | https://activemq.apache.org/security-advisories.data/CVE-2024-32114-announcement.txt |
| | | | | | https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31680 |
| | | | | | https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| Apache HTTP Server 代码问题漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| VMware Spring Framework 安全漏洞 | | | | | https://spring.io/security/cve-2024-38816 |
| | | | | | https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6 |
| | | | | | https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.1-36 |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://github.com/libexpat/libexpat |
| | | | | | https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674 |
| | | | | | https://www.php.net/downloads |
| | | | | | https://www.php.net/downloads |
| | | | | | https://access.redhat.com/security/cve/CVE-2024-5971 |
| Red Hat Undertow 资源管理错误漏洞 | | | | | https://bugzilla.redhat.com/show_bug.cgi?id=2293069 |
| | | | | | https://github.com/pypa/setuptools/releases/tag/v70.3 |
| | | | | | https://www.openssh.com/txt/release-9.8 |
| | | | | | |
| | | | | | https://curl.se/docs/CVE-2024-7264.html |
| Red Hat Undertow 竞争条件问题漏洞 | | | | | |
| | | | | | https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ |
| | | | | | https://jquery.com/upgrade-guide/3.5/ |
| | | | | | |
| | | | | | |
| | | | | | https://issues.apache.org/jira/browse/GROOVY-9824?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanel |
| Jakarta Expression Language 输入验证错误漏洞 | | | | | https://jakarta.ee/specifications/expression-language/3. |
| Sprymedia Datatables 跨站脚本漏洞 | | | | | https://github.com/DataTables/DataTables/releases/tag/1.10.21 |
| | | | | | https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwc |
| | | | | | https://github.com/jquery/jquery-ui/security/advisories/GHSA-j7qv-pgf6-hvh4 |
| | | | | | https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327 |
| | | | | | https://lists.apache.org/thread/6pjwm10bb69kq955fzr1n0nflnjd27dl |
| | | | | | https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9 |
| | | | | | https://github.com/jhy/jsoup/security/advisories/GHSA-gp7f-rwcx-9369 |
| | | | | | https://www.openssl.org/news/secadv/20230207.txt |
| | | | | | https://www.openssl.org/news/secadv/20230207.txt |
| | | | | | https://spring.io/security/cve-2023-20863 |
| | | | | | https://www.ntppool.org/zh/ |
| | | | | | https://www.ntppool.org/zh/ |
| | | | | | https://www.ntppool.org/zh/ |
| | | | | | https://www.ntppool.org/zh/ |
| | | | | | https://www.ntppool.org/zh/ |
| Intel oneAPI Toolkits 安全漏洞 | | | | | http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html |
| | | | | | https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-vh5c-xwqv-cv9g |
| | | | | | https://gitlab.gnome.org/GNOME/libxml2/-/commit/647e072ea0a2f12687fa05c172f4c4713fdb0c4f |
| | | | | | https://gitlab.gnome.org/GNOME/libxml2/-/commit/09a2dd453007f9c7205274623acdd73747c22d64 |
| | | | | | https://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bcc |
| | | | | | https://github.com/spring-projects/spring-boot/releases/tag/v3.0. |
| FasterXML jackson-databind 代码问题漏洞 | | | | | https://github.com/FasterXML/jackson-databind/issues/3972 |
| | | | | | https://github.com/pete4abw/lrzip-next/issues/132 |
| Apache Commons Compress 资源管理错误漏洞 | | | | | https://lists.apache.org/thread/5xwcyr600mn074vgxq92tjssrchmc93c |
| | | | | | https://support.apple.com/en-us/HT213981 |
| | | | | | https://support.apple.com/en-us/HT214035 |
| Apache Santuario 日志信息泄露漏洞 | | | | | https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55 |
| | | | | | https://www.openssh.com/openbsd.html |
| Python cryptography 代码问题漏洞 | | | | | https://github.com/pyca/cryptography/security/advisories/GHSA-jfhm-5ghh-2f97 |
| | | | | | https://www.openssh.com/txt/release-9.6 |
| | | | | | https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404 |
| | | | | | https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017 |
| | | | | | https://www.openssl.org/news/secadv/20240109.txt |
| | | | | | https://git.openssl.org/?p=openssl.git;a=commit;h=18c02492138d1eb8b6548cb26e7b625fb2414a2a |
| | | | | | https://sqlite.org/releaselog/3_44_2.html |
| | | | | | https://sqlite.org/forum/forumpost/4aa381993a |
| | | | | | https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85 |
| | | | | | https://support.apple.com/en-us/HT214089 |
| | | | | | https://support.apple.com/en-us/HT214089 |
| | | | | | https://support.apple.com/en-us/HT214089 |
| | | | | | https://support.apple.com/en-us/HT214089 |
| | | | | | https://github.com/nahsra/antisamy/releases/tag/v1.7.5 |
| | | | | | https://lists.apache.org/thread/96s5nqssj03rznz9hv58txdb2k1lr79k |
| | | | | | |
| | | | | | https://github.com/dnsjava/dnsjava/security/advisories/GHSA-cfxw-4h78-h7fw |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf |
| Apache Commons Compress 安全漏洞 | | | | | https://lists.apache.org/thread/ch5yo2d21p7vlqrhll9b17otbyq4npfg |
| | | | | | https://github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g |
| | | | | | https://support.apple.com/en-us/HT214101 |
| | | | | | https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q |
| | | | | | |
| | | | | | https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp |
| | | | | | https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01129.html |
| | | | | | https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c |
| | | | | | https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004 |
| | | | | | https://lists.apache.org/thread/4jtpsswn2r6xommol54p5mg263ysgdw2 |
| | | | | | https://my.f5.com/manage/s/article/K000139611 |
| | | | | | https://github.com/jasper-software/jasper/releases/tag/version-4.2.3 |
| | | | | | https://my.f5.com/manage/s/article/K000139609 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31678 |
| | | | | | https://sourceware.org/bugzilla/show_bug.cgi?id=31679 |
| | | | | | https://www.rarlab.com/rarnew.htm |
| | | | | | https://my.f5.com/manage/s/article/K000139627 |
| | | | | | https://my.f5.com/manage/s/article/K000139612 |
| | | | | | https://www.rarlab.com/rarnew.htm |
| Apache HTTP Server 代码问题漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | |
| | | | | | https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef |
| | | | | | https://github.com/urllib3/urllib3/security/advisories/GHSA-34jh-p97f-mpxf |
| Tiny Technologies TinyMCE 安全漏洞 | | | | | https://github.com/tinymce/tinymce/security/advisories/GHSA-9hcv-j9pv-qmph |
| Tiny Technologies TinyMCE 安全漏洞 | | | | | https://github.com/tinymce/tinymce/security/advisories/GHSA-w9jx-4g6g-rp7x |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://lists.apache.org/thread/p2xfjsvpogyrg4hw9cjs2nrnqnl34qf0 |
| | | | | | https://spring.io/security/cve-2024-38808 |
| VMware Spring Framework 安全漏洞 | | | | | https://spring.io/security/cve-2024-38809 |
| | | | | | https://github.com/requirejs/r.js |
| Apache HTTP Server 输入验证错误漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| Apache HTTP Server 代码问题漏洞 | | | | | https://httpd.apache.org/security/vulnerabilities_24.html |
| | | | | | https://lists.apache.org/thread/vwf1ot8wx1njyy8n19j5j2tcnjnozt3b |
| | | | | | https://www.jenkins.io/security/advisory/2024-08-07/#SECURITY-3349 |
| | | | | | https://github.com/ckeditor/ckeditor4/releases/tag/4.25.0-l |
| | | | | | https://github.com/openssl/openssl |
| | | | | | https://openssl-library.org/news/secadv/20240903.txt |
| | | | | | https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf |
| | | | | | https://github.com/jeremyhylton/cpython/commit/1587608515127032778669c8232d46ec6d8f593c |
| | | | | | https://github.com/google/guava/issues/4011 |
| | | | | | https://www.openssh.com/security.html |
| | | | | Python Packaging Authority | https://github.com/pypa/pip/releases/tag/23.3.1 |
| | | | | | https://www.libssh.org/files/0.10/ |
| | | | | | https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/ |
| | | | | | https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2 |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://nodejs.org/en/blog/vulnerability/july-2024-security-releases |
| | | | | | https://github.com/ckeditor/ckeditor4/releases/tag/4.25.0-l |
| | | | | | https://www.openssl.org/news/secadv/20240516.txt |
| | | | | | https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87 |