docker.io/apache/ranger:2.8.0 linux/amd64

docker.io/apache/ranger:2.8.0 - Trivy安全扫描结果 扫描时间: 2026-07-03 02:23
全部漏洞信息
低危漏洞:133 中危漏洞:436 高危漏洞:144 严重漏洞:13

系统OS: ubuntu 22.04 扫描引擎: Trivy 扫描时间: 2026-07-03 02:23

docker.io/apache/ranger:2.8.0 (ubuntu 22.04) (ubuntu)
低危漏洞:112 中危漏洞:294 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
libssl3 CVE-2026-45447 高危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45447

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-07-01 13:17

openssl CVE-2026-45447 高危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45447

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-07-01 13:17

bind9-host CVE-2026-3592 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: Amplification vulnerabilities via self-pointed glue records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3592

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-17 10:43

bind9-host CVE-2026-5946 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: BIND: Denial of Service via specially crafted DNS messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5946

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-30 03:21

bind9-host CVE-2026-5950 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: Unbounded resend loop in BIND 9 resolver

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5950

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-17 10:59

bind9-libs CVE-2026-1519 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.3 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1519

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-25 14:16 修改: 2026-06-30 03:17

bind9-libs CVE-2026-3039 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3039

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-30 03:19

bind9-libs CVE-2026-3592 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: Amplification vulnerabilities via self-pointed glue records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3592

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-17 10:43

bind9-libs CVE-2026-5946 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: BIND: Denial of Service via specially crafted DNS messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5946

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-30 03:21

bind9-libs CVE-2026-5950 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: Unbounded resend loop in BIND 9 resolver

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5950

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-17 10:59

bsdutils CVE-2026-27456 中危 1:2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

curl CVE-2025-14017 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14017

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:35

curl CVE-2026-11856 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11856

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl CVE-2026-1965 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1965

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:15 修改: 2026-06-17 10:16

curl CVE-2026-3783 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3783

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:16 修改: 2026-06-17 10:44

curl CVE-2026-5545 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:59

curl CVE-2026-6253 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

curl CVE-2026-6429 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

curl CVE-2026-7168 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:01

curl CVE-2026-8925 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8925

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl CVE-2026-8927 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8927

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libblkid1 CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

libc-bin CVE-2025-15281 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-20 14:16 修改: 2026-06-17 08:37

libc-bin CVE-2026-0861 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: Integer overflow in memalign leads to heap corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0861

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-14 21:15 修改: 2026-06-17 10:11

libc-bin CVE-2026-0915 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-15 22:16 修改: 2026-06-17 10:11

libc-bin CVE-2026-4046 中危 2.35-0ubuntu3.11 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-03-30 18:16 修改: 2026-06-17 10:55

libc-bin CVE-2026-5435 中危 2.35-0ubuntu3.11 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-28 13:19 修改: 2026-06-17 10:59

libc-bin CVE-2026-6238 中危 2.35-0ubuntu3.11 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-28 19:37 修改: 2026-06-19 21:17

libc6 CVE-2025-15281 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-20 14:16 修改: 2026-06-17 08:37

libc6 CVE-2026-0861 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: Integer overflow in memalign leads to heap corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0861

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-14 21:15 修改: 2026-06-17 10:11

libc6 CVE-2026-0915 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-15 22:16 修改: 2026-06-17 10:11

libc6 CVE-2026-4046 中危 2.35-0ubuntu3.11 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-03-30 18:16 修改: 2026-06-17 10:55

libc6 CVE-2026-5435 中危 2.35-0ubuntu3.11 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-28 13:19 修改: 2026-06-17 10:59

libc6 CVE-2026-6238 中危 2.35-0ubuntu3.11 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-28 19:37 修改: 2026-06-19 21:17

libcap2 CVE-2026-4878 中危 1:2.44-1ubuntu0.22.04.2 1:2.44-1ubuntu0.22.04.3 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4878

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-09 16:16 修改: 2026-07-01 19:16

libcap2-bin CVE-2026-4878 中危 1:2.44-1ubuntu0.22.04.2 1:2.44-1ubuntu0.22.04.3 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4878

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-09 16:16 修改: 2026-07-01 19:16

libcurl4 CVE-2025-14017 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14017

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:35

libcurl4 CVE-2026-11856 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11856

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libcurl4 CVE-2026-1965 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1965

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:15 修改: 2026-06-17 10:16

libcurl4 CVE-2026-3783 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3783

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:16 修改: 2026-06-17 10:44

libcurl4 CVE-2026-5545 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:59

libcurl4 CVE-2026-6253 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

libcurl4 CVE-2026-6429 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

libcurl4 CVE-2026-7168 中危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:01

libcurl4 CVE-2026-8925 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8925

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libcurl4 CVE-2026-8927 中危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8927

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libexpat1 CVE-2025-66382 中危 2.4.7-1ubuntu0.6 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2025-11-28 07:15 修改: 2026-06-17 09:56

libexpat1 CVE-2026-24515 中危 2.4.7-1ubuntu0.6 2.4.7-1ubuntu0.7 libexpat: libexpat null pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24515

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-23 08:16 修改: 2026-06-17 10:23

libexpat1 CVE-2026-25210 中危 2.4.7-1ubuntu0.6 2.4.7-1ubuntu0.7 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25210

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-30 07:16 修改: 2026-06-17 10:24

libgcrypt20 CVE-2026-41989 中危 1.9.4-3ubuntu3 1.9.4-3ubuntu3.2 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41989

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-23 05:16 修改: 2026-06-17 10:47

libgnutls30 CVE-2025-14831 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.8 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14831

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-02-09 15:16 修改: 2026-06-30 00:16

libgnutls30 CVE-2026-33845 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33845

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-30 18:16 修改: 2026-07-01 20:17

libgnutls30 CVE-2026-33846 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33846

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-04 10:15 修改: 2026-07-01 20:17

libgnutls30 CVE-2026-3832 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3832

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-30 18:16 修改: 2026-06-24 17:16

libgnutls30 CVE-2026-3833 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3833

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-30 18:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42009 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42009

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-18 13:16 修改: 2026-07-01 20:17

libgnutls30 CVE-2026-42010 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Authentication Bypass via NUL Character in Username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42010

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-07 12:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42011 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Security bypass due to incorrect name constraint handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42011

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-07 15:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42012 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42012

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 22:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42013 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42013

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 22:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42014 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42014

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-16 02:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-42015 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42015

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 22:16 修改: 2026-06-30 03:19

libgnutls30 CVE-2026-5260 中危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.9 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5260

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 22:16 修改: 2026-06-30 03:21

liblmdb0 CVE-2026-22185 中危 0.9.24-1build2 OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer Underflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22185

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-07 21:16 修改: 2026-06-17 10:19

libmount1 CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

libnghttp2-14 CVE-2026-27135 中危 1.43.0-1ubuntu0.2 1.43.0-1ubuntu0.3 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27135

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-18 18:16 修改: 2026-06-30 03:17

libp11-kit0 CVE-2026-13757 中危 0.24.0-6build1 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13757

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-29 19:16 修改: 2026-07-01 15:16

libperl5.34 CVE-2026-42496 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42496

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 02:16 修改: 2026-06-30 03:19

libperl5.34 CVE-2026-8376 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 Perl versions through 5.43.10 have a heap buffer overflow when compili ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8376

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 00:16 修改: 2026-06-17 11:03

libpng16-16 CVE-2026-25646 中危 1.6.37-3ubuntu0.3 1.6.37-3ubuntu0.4 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25646

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-02-10 18:16 修改: 2026-06-30 03:17

libpng16-16 CVE-2026-33416 中危 1.6.37-3ubuntu0.3 1.6.37-3ubuntu0.5 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33416

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 17:16 修改: 2026-06-17 10:37

libpng16-16 CVE-2026-33636 中危 1.6.37-3ubuntu0.3 1.6.37-3ubuntu0.5 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33636

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 17:16 修改: 2026-06-17 10:37

libpng16-16 CVE-2026-34757 中危 1.6.37-3ubuntu0.3 1.6.37-3ubuntu0.5 libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34757

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-09 15:16 修改: 2026-06-17 10:39

libpng16-16 CVE-2026-40930 中危 1.6.37-3ubuntu0.3 LIBPNG is a reference library for use in applications that process PNG ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40930

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-04 16:16 修改: 2026-06-17 10:45

libpython3.10 CVE-2025-11468 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Missing character filtering in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11468

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:30

libpython3.10 CVE-2025-12084 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12084

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-03 19:15 修改: 2026-06-17 08:31

libpython3.10 CVE-2025-13837 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Out-of-memory when loading Plist

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13837

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-01 18:16 修改: 2026-06-17 08:34

libpython3.10 CVE-2025-15282 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection via newlines in data URL mediatype in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15282

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:37

libpython3.10 CVE-2026-0672 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection in http.cookies.Morsel in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0672

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10 CVE-2026-0865 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: wsgiref.headers.Headers allows header newline injection in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0865

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10 CVE-2026-2297 中危 3.10.12-1~22.04.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-04 23:16 修改: 2026-06-17 10:30

libpython3.10-minimal CVE-2025-11468 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Missing character filtering in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11468

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:30

libpython3.10-minimal CVE-2025-12084 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12084

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-03 19:15 修改: 2026-06-17 08:31

libpython3.10-minimal CVE-2025-13837 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Out-of-memory when loading Plist

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13837

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-01 18:16 修改: 2026-06-17 08:34

libpython3.10-minimal CVE-2025-15282 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection via newlines in data URL mediatype in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15282

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:37

libpython3.10-minimal CVE-2026-0672 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection in http.cookies.Morsel in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0672

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10-minimal CVE-2026-0865 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: wsgiref.headers.Headers allows header newline injection in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0865

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10-minimal CVE-2026-2297 中危 3.10.12-1~22.04.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-04 23:16 修改: 2026-06-17 10:30

libpython3.10-stdlib CVE-2025-11468 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Missing character filtering in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11468

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:30

libpython3.10-stdlib CVE-2025-12084 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12084

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-03 19:15 修改: 2026-06-17 08:31

libpython3.10-stdlib CVE-2025-13837 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Out-of-memory when loading Plist

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13837

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-01 18:16 修改: 2026-06-17 08:34

libpython3.10-stdlib CVE-2025-15282 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection via newlines in data URL mediatype in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15282

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:37

libpython3.10-stdlib CVE-2026-0672 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection in http.cookies.Morsel in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0672

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10-stdlib CVE-2026-0865 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: wsgiref.headers.Headers allows header newline injection in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0865

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

libpython3.10-stdlib CVE-2026-2297 中危 3.10.12-1~22.04.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-04 23:16 修改: 2026-06-17 10:30

libsmartcols1 CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

libsqlite3-0 CVE-2026-11822 中危 3.37.2-2ubuntu0.5 3.37.2-2ubuntu0.6 SQLite before 3.53.2 contains memory corruption vulnerabilities in the ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11822

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 20:16 修改: 2026-06-17 10:14

libsqlite3-0 CVE-2026-11824 中危 3.37.2-2ubuntu0.5 3.37.2-2ubuntu0.6 SQLite before 3.53.2 contains a heap-based buffer overflow vulnerabili ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11824

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 20:16 修改: 2026-06-17 10:14

libssh-4 CVE-2026-0964 中危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: Improper sanitation of paths received from SCP servers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0964

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 21:17 修改: 2026-06-17 10:11

libssh-4 CVE-2026-0967 中危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: libssh: Denial of Service via inefficient regular expression processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0967

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 21:17 修改: 2026-06-17 10:11

libssh-4 CVE-2026-0968 中危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: libssh: Denial of Service due to malformed SFTP message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0968

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 21:17 修改: 2026-06-17 10:11

libssh-4 CVE-2026-3731 中危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.7 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3731

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-08 11:15 修改: 2026-06-17 10:44

bind9-host CVE-2026-1519 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.3 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1519

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-25 14:16 修改: 2026-06-30 03:17

libssl3 CVE-2025-15467 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15467

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-30 03:16

libssl3 CVE-2026-31790 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

libssl3 CVE-2026-34182 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34182

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:38

libssl3 CVE-2026-45445 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: AES-OCB IV Ignored on EVP_Cipher() Path

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45445

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:52

libsystemd0 CVE-2026-29111 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.19 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-03-23 22:16 修改: 2026-06-17 10:29

libsystemd0 CVE-2026-40225 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.19 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

libsystemd0 CVE-2026-40226 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.21 systemd: systemd nspawn: Escape-to-host action via crafted config file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40226

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

libtasn1-6 CVE-2025-13151 中危 4.18.0-4ubuntu0.1 4.18.0-4ubuntu0.2 libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13151

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-07 22:15 修改: 2026-06-17 08:33

libudev1 CVE-2026-29111 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.19 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-03-23 22:16 修改: 2026-06-17 10:29

libudev1 CVE-2026-40225 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.19 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

libudev1 CVE-2026-40226 中危 249.11-0ubuntu3.17 249.11-0ubuntu3.21 systemd: systemd nspawn: Escape-to-host action via crafted config file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40226

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

libuuid1 CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

libxml2 CVE-2026-6653 中危 2.9.13+dfsg-1ubuntu0.11 2.9.13+dfsg-1ubuntu0.12 libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6653

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-22 14:17 修改: 2026-06-22 18:16

libxslt1.1 CVE-2025-10911 中危 1.1.34-4ubuntu0.22.04.5 libxslt: use-after-free with key data stored cross-RVT

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10911

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-09-25 16:15 修改: 2026-06-30 00:16

locales CVE-2025-15281 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-20 14:16 修改: 2026-06-17 08:37

locales CVE-2026-0861 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: Integer overflow in memalign leads to heap corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0861

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-14 21:15 修改: 2026-06-17 10:11

locales CVE-2026-0915 中危 2.35-0ubuntu3.11 2.35-0ubuntu3.13 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-15 22:16 修改: 2026-06-17 10:11

locales CVE-2026-4046 中危 2.35-0ubuntu3.11 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-30 18:16 修改: 2026-06-17 10:55

locales CVE-2026-5435 中危 2.35-0ubuntu3.11 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-28 13:19 修改: 2026-06-17 10:59

locales CVE-2026-6238 中危 2.35-0ubuntu3.11 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-28 19:37 修改: 2026-06-19 21:17

mount CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

openssh-client CVE-2026-3497 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-12 19:16 修改: 2026-06-30 03:19

openssh-client CVE-2026-35385 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-30 03:19

openssh-client CVE-2026-35386 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-client CVE-2026-35387 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-client CVE-2026-35388 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-client CVE-2026-35414 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 18:16 修改: 2026-06-17 10:40

openssh-client CVE-2026-55655 中危 1:8.9p1-3ubuntu0.13 openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55655

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 18:16

openssh-server CVE-2026-3497 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-12 19:16 修改: 2026-06-30 03:19

openssh-server CVE-2026-35385 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-30 03:19

openssh-server CVE-2026-35386 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-server CVE-2026-35387 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-server CVE-2026-35388 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-server CVE-2026-35414 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 18:16 修改: 2026-06-17 10:40

openssh-server CVE-2026-55655 中危 1:8.9p1-3ubuntu0.13 openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55655

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 18:16

openssh-sftp-server CVE-2026-3497 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-12 19:16 修改: 2026-06-30 03:19

openssh-sftp-server CVE-2026-35385 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-30 03:19

openssh-sftp-server CVE-2026-35386 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-sftp-server CVE-2026-35387 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-sftp-server CVE-2026-35388 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

openssh-sftp-server CVE-2026-35414 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 18:16 修改: 2026-06-17 10:40

openssh-sftp-server CVE-2026-55655 中危 1:8.9p1-3ubuntu0.13 openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55655

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 18:16

bind9-host CVE-2026-3039 中危 1:9.18.39-0ubuntu0.22.04.2 1:9.18.39-0ubuntu0.22.04.4 bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3039

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-20 13:16 修改: 2026-06-30 03:19

openssl CVE-2025-15467 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15467

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-30 03:16

openssl CVE-2026-31790 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

openssl CVE-2026-34182 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34182

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:38

openssl CVE-2026-45445 中危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: AES-OCB IV Ignored on EVP_Cipher() Path

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45445

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:52

p11-kit CVE-2026-13757 中危 0.24.0-6build1 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13757

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-29 19:16 修改: 2026-07-01 15:16

p11-kit-modules CVE-2026-13757 中危 0.24.0-6build1 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13757

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-29 19:16 修改: 2026-07-01 15:16

perl CVE-2026-42496 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42496

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 02:16 修改: 2026-06-30 03:19

perl CVE-2026-8376 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 Perl versions through 5.43.10 have a heap buffer overflow when compili ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8376

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 00:16 修改: 2026-06-17 11:03

perl-base CVE-2026-42496 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42496

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 02:16 修改: 2026-06-30 03:19

perl-base CVE-2026-8376 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 Perl versions through 5.43.10 have a heap buffer overflow when compili ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8376

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-05-26 00:16 修改: 2026-06-17 11:03

perl-modules-5.34 CVE-2026-42496 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42496

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 02:16 修改: 2026-06-30 03:19

perl-modules-5.34 CVE-2026-8376 中危 5.34.0-3ubuntu1.5 5.34.0-3ubuntu1.7 Perl versions through 5.43.10 have a heap buffer overflow when compili ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8376

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-26 00:16 修改: 2026-06-17 11:03

python3-pip CVE-2024-35195 中危 22.0.2+dfsg-1ubuntu0.7 requests: subsequent requests to the same host ignore cert verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-35195

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2024-05-20 21:15 修改: 2026-06-17 07:34

python3-pip CVE-2025-66418 中危 22.0.2+dfsg-1ubuntu0.7 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66418

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-05 16:15 修改: 2026-06-17 09:56

python3-pip CVE-2025-66471 中危 22.0.2+dfsg-1ubuntu0.7 urllib3: urllib3 Streaming API improperly handles highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66471

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-05 17:16 修改: 2026-06-17 09:56

python3-pip CVE-2026-21441 中危 22.0.2+dfsg-1ubuntu0.7 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21441

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-07 22:15 修改: 2026-07-01 13:16

python3.10 CVE-2025-11468 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Missing character filtering in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11468

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:30

python3.10 CVE-2025-12084 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12084

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-03 19:15 修改: 2026-06-17 08:31

python3.10 CVE-2025-13837 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Out-of-memory when loading Plist

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13837

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-01 18:16 修改: 2026-06-17 08:34

python3.10 CVE-2025-15282 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection via newlines in data URL mediatype in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15282

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:37

python3.10 CVE-2026-0672 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection in http.cookies.Morsel in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0672

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

python3.10 CVE-2026-0865 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: wsgiref.headers.Headers allows header newline injection in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0865

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

python3.10 CVE-2026-2297 中危 3.10.12-1~22.04.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-04 23:16 修改: 2026-06-17 10:30

python3.10-minimal CVE-2025-11468 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Missing character filtering in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11468

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:30

python3.10-minimal CVE-2025-12084 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12084

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-03 19:15 修改: 2026-06-17 08:31

python3.10-minimal CVE-2025-13837 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Out-of-memory when loading Plist

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13837

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-12-01 18:16 修改: 2026-06-17 08:34

python3.10-minimal CVE-2025-15282 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection via newlines in data URL mediatype in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15282

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 08:37

python3.10-minimal CVE-2026-0672 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: Header injection in http.cookies.Morsel in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0672

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

python3.10-minimal CVE-2026-0865 中危 3.10.12-1~22.04.13 3.10.12-1~22.04.14 cpython: wsgiref.headers.Headers allows header newline injection in Python

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0865

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-01-20 22:15 修改: 2026-06-17 10:11

python3.10-minimal CVE-2026-2297 中危 3.10.12-1~22.04.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-04 23:16 修改: 2026-06-17 10:30

sed CVE-2026-5958 中危 4.8-1ubuntu2 4.8-1ubuntu2.1 sed: GNU sed TOCTOU race condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5958

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-20 12:16 修改: 2026-06-17 10:59

ssh CVE-2026-3497 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-12 19:16 修改: 2026-06-30 03:19

ssh CVE-2026-35385 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-30 03:19

ssh CVE-2026-35386 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

ssh CVE-2026-35387 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

ssh CVE-2026-35388 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 17:16 修改: 2026-06-17 10:40

ssh CVE-2026-35414 中危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.15 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-02 18:16 修改: 2026-06-17 10:40

ssh CVE-2026-55655 中危 1:8.9p1-3ubuntu0.13 openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55655

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 18:16

tar CVE-2025-45582 中危 1.34+dfsg-1ubuntu0.1.22.04.2 tar: Tar path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-45582

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2025-07-11 17:15 修改: 2026-06-17 09:25

tar CVE-2026-5704 中危 1.34+dfsg-1ubuntu0.1.22.04.2 1.34+dfsg-1ubuntu0.1.22.04.3 tar: tar: Hidden file injection via crafted archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5704

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-06 16:16 修改: 2026-06-17 10:59

util-linux CVE-2026-27456 中危 2.37.2-4ubuntu3.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

vim CVE-2026-28417 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28417

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-28418 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28418

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-28419 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via malformed tags file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28419

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-28420 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28420

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-28421 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Denial of service and information disclosure via crafted swap file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28421

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-28422 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28422

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim CVE-2026-33412 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: Vim: Arbitrary code execution via command injection in glob() function

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33412

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-24 20:16 修改: 2026-06-30 03:18

vim CVE-2026-34982 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: arbitrary command execution via modeline sandbox bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34982

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 16:16 修改: 2026-06-30 13:18

vim CVE-2026-35177 中危 2:8.2.3995-1ubuntu2.24 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35177

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 18:16 修改: 2026-06-17 10:40

vim CVE-2026-39881 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.28 vim: Vim: Arbitrary code execution via command injection in NetBeans interface

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39881

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-08 21:17 修改: 2026-06-17 10:42

vim CVE-2026-41411 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.29 vim: Vim: Command injection allows arbitrary code execution via malicious tag files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41411

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-24 17:16 修改: 2026-06-17 10:46

vim CVE-2026-42307 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 Vim: Vim: Arbitrary code execution via OS command injection in netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42307

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:47

vim CVE-2026-43961 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43961

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vim CVE-2026-44656 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Arbitrary command execution via :find command-line completion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44656

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim CVE-2026-45130 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45130

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim CVE-2026-46483 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31 vim: command injection when decompressing .tgz archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46483

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-15 15:16 修改: 2026-06-17 10:53

vim CVE-2026-47162 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary Code Execution via crafted directory names

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47162

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim CVE-2026-47167 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47167

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:54

vim CVE-2026-52858 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52858

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim CVE-2026-52859 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Denial of Service via out-of-bounds write in terminal handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52859

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim CVE-2026-52860 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary code execution through Python omni-completion.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52860

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim CVE-2026-55693 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55693

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 14:17

vim CVE-2026-55892 中危 2:8.2.3995-1ubuntu2.24 vim: Vim: Denial of Service via crafted spell file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55892

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 19:16

vim CVE-2026-55895 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55895

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

vim CVE-2026-57452 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0671, wh ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57452

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:12

vim CVE-2026-57455 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0698, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57455

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:23

vim CVE-2026-57456 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57456

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

vim-common CVE-2026-28417 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28417

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-28418 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28418

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-28419 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via malformed tags file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28419

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-28420 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28420

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-28421 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Denial of service and information disclosure via crafted swap file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28421

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-28422 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28422

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-common CVE-2026-33412 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: Vim: Arbitrary code execution via command injection in glob() function

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33412

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-24 20:16 修改: 2026-06-30 03:18

vim-common CVE-2026-34982 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: arbitrary command execution via modeline sandbox bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34982

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 16:16 修改: 2026-06-30 13:18

vim-common CVE-2026-35177 中危 2:8.2.3995-1ubuntu2.24 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35177

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 18:16 修改: 2026-06-17 10:40

vim-common CVE-2026-39881 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.28 vim: Vim: Arbitrary code execution via command injection in NetBeans interface

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39881

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-08 21:17 修改: 2026-06-17 10:42

vim-common CVE-2026-41411 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.29 vim: Vim: Command injection allows arbitrary code execution via malicious tag files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41411

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-24 17:16 修改: 2026-06-17 10:46

vim-common CVE-2026-42307 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 Vim: Vim: Arbitrary code execution via OS command injection in netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42307

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:47

vim-common CVE-2026-43961 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43961

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vim-common CVE-2026-44656 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Arbitrary command execution via :find command-line completion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44656

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim-common CVE-2026-45130 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45130

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim-common CVE-2026-46483 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31 vim: command injection when decompressing .tgz archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46483

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-15 15:16 修改: 2026-06-17 10:53

vim-common CVE-2026-47162 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary Code Execution via crafted directory names

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47162

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim-common CVE-2026-47167 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47167

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:54

vim-common CVE-2026-52858 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52858

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim-common CVE-2026-52859 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Denial of Service via out-of-bounds write in terminal handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52859

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim-common CVE-2026-52860 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary code execution through Python omni-completion.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52860

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim-common CVE-2026-55693 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55693

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 14:17

vim-common CVE-2026-55892 中危 2:8.2.3995-1ubuntu2.24 vim: Vim: Denial of Service via crafted spell file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55892

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 19:16

vim-common CVE-2026-55895 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55895

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

vim-common CVE-2026-57452 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0671, wh ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57452

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:12

vim-common CVE-2026-57455 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0698, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57455

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:23

vim-common CVE-2026-57456 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57456

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

vim-runtime CVE-2026-28417 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28417

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-28418 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28418

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-28419 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via malformed tags file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28419

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-28420 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28420

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-28421 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Denial of service and information disclosure via crafted swap file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28421

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-28422 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28422

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

vim-runtime CVE-2026-33412 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: Vim: Arbitrary code execution via command injection in glob() function

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33412

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-24 20:16 修改: 2026-06-30 03:18

vim-runtime CVE-2026-34982 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: arbitrary command execution via modeline sandbox bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34982

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 16:16 修改: 2026-06-30 13:18

vim-runtime CVE-2026-35177 中危 2:8.2.3995-1ubuntu2.24 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35177

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 18:16 修改: 2026-06-17 10:40

vim-runtime CVE-2026-39881 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.28 vim: Vim: Arbitrary code execution via command injection in NetBeans interface

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39881

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-08 21:17 修改: 2026-06-17 10:42

vim-runtime CVE-2026-41411 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.29 vim: Vim: Command injection allows arbitrary code execution via malicious tag files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41411

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-24 17:16 修改: 2026-06-17 10:46

vim-runtime CVE-2026-42307 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 Vim: Vim: Arbitrary code execution via OS command injection in netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42307

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:47

vim-runtime CVE-2026-43961 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43961

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vim-runtime CVE-2026-44656 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Arbitrary command execution via :find command-line completion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44656

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim-runtime CVE-2026-45130 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45130

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

vim-runtime CVE-2026-46483 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31 vim: command injection when decompressing .tgz archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46483

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-15 15:16 修改: 2026-06-17 10:53

vim-runtime CVE-2026-47162 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary Code Execution via crafted directory names

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47162

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim-runtime CVE-2026-47167 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47167

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:54

vim-runtime CVE-2026-52858 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52858

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim-runtime CVE-2026-52859 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Denial of Service via out-of-bounds write in terminal handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52859

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

vim-runtime CVE-2026-52860 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary code execution through Python omni-completion.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52860

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

vim-runtime CVE-2026-55693 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55693

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 14:17

vim-runtime CVE-2026-55892 中危 2:8.2.3995-1ubuntu2.24 vim: Vim: Denial of Service via crafted spell file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55892

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 19:16

vim-runtime CVE-2026-55895 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55895

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

vim-runtime CVE-2026-57452 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0671, wh ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57452

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:12

vim-runtime CVE-2026-57455 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0698, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57455

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:23

vim-runtime CVE-2026-57456 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57456

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

wget CVE-2021-31879 中危 1.21.2-2ubuntu1.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2021-04-29 05:15 修改: 2026-06-17 03:52

xxd CVE-2026-28417 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28417

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-28418 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28418

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-28419 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via malformed tags file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28419

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-28420 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28420

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-28421 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Denial of service and information disclosure via crafted swap file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28421

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-28422 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28422

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-27 22:16 修改: 2026-06-17 10:28

xxd CVE-2026-33412 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: Vim: Arbitrary code execution via command injection in glob() function

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33412

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-03-24 20:16 修改: 2026-06-30 03:18

xxd CVE-2026-34982 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.27 vim: arbitrary command execution via modeline sandbox bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34982

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 16:16 修改: 2026-06-30 13:18

xxd CVE-2026-35177 中危 2:8.2.3995-1ubuntu2.24 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35177

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-06 18:16 修改: 2026-06-17 10:40

xxd CVE-2026-39881 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.28 vim: Vim: Arbitrary code execution via command injection in NetBeans interface

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39881

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-08 21:17 修改: 2026-06-17 10:42

xxd CVE-2026-41411 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.29 vim: Vim: Command injection allows arbitrary code execution via malicious tag files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41411

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-04-24 17:16 修改: 2026-06-17 10:46

xxd CVE-2026-42307 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 Vim: Vim: Arbitrary code execution via OS command injection in netrw plugin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42307

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:47

xxd CVE-2026-43961 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43961

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

xxd CVE-2026-44656 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Arbitrary command execution via :find command-line completion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44656

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

xxd CVE-2026-45130 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.30 vim: Vim: Heap buffer overflow allows arbitrary code execution or denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45130

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-08 23:16 修改: 2026-06-17 10:51

xxd CVE-2026-46483 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.31 vim: command injection when decompressing .tgz archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46483

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-05-15 15:16 修改: 2026-06-17 10:53

xxd CVE-2026-47162 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary Code Execution via crafted directory names

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47162

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

xxd CVE-2026-47167 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47167

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:54

xxd CVE-2026-52858 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 Vim is an open source, command line text editor. Prior to version 9.2. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52858

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

xxd CVE-2026-52859 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Denial of Service via out-of-bounds write in terminal handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52859

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-17 10:57

xxd CVE-2026-52860 中危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.32 vim: Vim: Arbitrary code execution through Python omni-completion.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-52860

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-11 19:16 修改: 2026-06-30 03:20

xxd CVE-2026-55693 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55693

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 14:17

xxd CVE-2026-55892 中危 2:8.2.3995-1ubuntu2.24 vim: Vim: Denial of Service via crafted spell file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55892

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 19:16

xxd CVE-2026-55895 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55895

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

xxd CVE-2026-57452 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0671, wh ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57452

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:12

xxd CVE-2026-57455 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0698, th ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57455

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 04:23

xxd CVE-2026-57456 中危 2:8.2.3995-1ubuntu2.24 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-57456

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-25 16:16 修改: 2026-06-26 05:16

ncurses-base CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-12 15:15 修改: 2026-06-17 06:39

ncurses-bin CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-12 15:15 修改: 2026-06-17 06:39

curl CVE-2026-8458 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8458

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libcurl4 CVE-2025-0167 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2025-02-05 10:15 修改: 2026-06-17 08:25

libcurl4 CVE-2025-14524 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:36

libcurl4 CVE-2025-15079 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: Host verification bypass during SSH transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:37

libgnutls30 CVE-2025-9820 低危 3.7.3-4ubuntu1.7 3.7.3-4ubuntu1.8 gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9820

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-26 20:16 修改: 2026-06-30 09:16

libicu70 CVE-2025-5222 低危 70.1-2 icu: Stack buffer overflow in the SRBRoot::addTag function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5222

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-05-27 21:15 修改: 2026-06-30 05:17

libcurl4 CVE-2025-15224 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: libssh key passphrase bypass without agent set

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:37

openssh-client CVE-2025-61984 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-client CVE-2025-61985 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-client CVE-2026-55654 低危 1:8.9p1-3ubuntu0.13 openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55654

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 16:59

liblzma5 CVE-2026-34743 低危 5.2.5-2ubuntu1 5.2.5-2ubuntu1.1 xz: XZ Utils: Denial of Service via buffer overflow in index decoding

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34743

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-02 19:21 修改: 2026-06-17 10:39

libcurl4 CVE-2026-12064 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12064

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libncurses6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-12 15:15 修改: 2026-06-17 06:39

libncursesw6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-12 15:15 修改: 2026-06-17 06:39

libcurl4 CVE-2026-3784 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3784

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:16 修改: 2026-06-17 10:44

libcurl4 CVE-2026-4873 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:57

libpcre2-8-0 CVE-2022-41409 低危 10.39-3ubuntu0.1 pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-41409

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-07-18 14:15 修改: 2026-06-17 05:03

openssh-server CVE-2025-61984 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-server CVE-2025-61985 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-server CVE-2026-55654 低危 1:8.9p1-3ubuntu0.13 openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55654

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 16:59

vim CVE-2026-25749 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via 'helpfile' option processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25749

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-06 23:15 修改: 2026-06-17 10:25

vim CVE-2026-26269 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Netbeans specialKeys stack buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26269

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-13 20:17 修改: 2026-06-17 10:26

libssh-4 CVE-2025-8277 低危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: Memory Exhaustion via Repeated Key Exchange in libssh

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8277

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2025-09-09 12:15 修改: 2026-06-30 09:16

libssh-4 CVE-2026-0965 低危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: libssh: Denial of Service via improper configuration file handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0965

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 21:17 修改: 2026-06-17 10:11

libssh-4 CVE-2026-0966 低危 0.9.6-2ubuntu0.22.04.5 0.9.6-2ubuntu0.22.04.6 libssh: libssh: Denial of Service via zero-length input in ssh_get_hexa()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0966

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-26 21:17 修改: 2026-06-17 10:11

libpcre3 CVE-2017-11164 低危 2:8.39-13ubuntu0.22.04.1 pcre: OP_KETRMAX feature in the match function in pcre_exec.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-11164

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2017-07-11 03:29 修改: 2026-06-17 01:01

libcurl4 CVE-2026-5773 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:59

libcurl4 CVE-2026-6276 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

libcurl4 CVE-2026-8286 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8286

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

openssh-sftp-server CVE-2025-61984 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-sftp-server CVE-2025-61985 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

openssh-sftp-server CVE-2026-55654 低危 1:8.9p1-3ubuntu0.13 openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55654

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 16:59

libcurl4 CVE-2026-8458 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8458

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libssl3 CVE-2025-68160 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68160

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:58

libssl3 CVE-2025-69418 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69418

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2025-69419 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2025-69420 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via malformed TimeStamp Response

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69420

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-68160 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68160

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:58

openssl CVE-2025-69418 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69418

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-69419 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-69420 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via malformed TimeStamp Response

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69420

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-69421 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69421

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2026-22795 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22795

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

openssl CVE-2026-22796 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22796

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

openssl CVE-2026-28387 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28388 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28389 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28390 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-31789 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

vim-common CVE-2026-25749 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via 'helpfile' option processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25749

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-06 23:15 修改: 2026-06-17 10:25

vim-common CVE-2026-26269 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Netbeans specialKeys stack buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26269

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-13 20:17 修改: 2026-06-17 10:26

openssl CVE-2026-34180 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34180

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:38

openssl CVE-2026-42766 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Possible NULL Dereference in Password-Based CMS Decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42766

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

openssl CVE-2026-42767 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42767

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

openssl CVE-2026-42770 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: FFC-DH Peer Validation Uses Attacker-Supplied q

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42770

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

openssl CVE-2026-45446 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45446

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:52

openssl CVE-2026-7383 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7383

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 11:02

openssl CVE-2026-9076 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9076

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-06-09 17:17 修改: 2026-06-17 11:04

libssl3 CVE-2025-69421 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69421

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2026-22795 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22795

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

passwd CVE-2023-29383 低危 1:4.8.1-2ubuntu2.2 shadow: Improper input validation in shadow-utils package utility chfn

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-29383

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-04-14 22:15 修改: 2026-06-17 05:49

passwd CVE-2024-56433 低危 1:4.8.1-2ubuntu2.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2024-12-26 09:15 修改: 2026-06-17 08:12

libssl3 CVE-2026-22796 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.21 openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22796

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

libssl3 CVE-2026-28387 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28388 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28389 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28390 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-31789 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.23 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

libssl3 CVE-2026-34180 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34180

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:38

libssl3 CVE-2026-42766 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Possible NULL Dereference in Password-Based CMS Decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42766

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

libssl3 CVE-2026-42767 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42767

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

libssl3 CVE-2026-42770 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: FFC-DH Peer Validation Uses Attacker-Supplied q

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42770

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:48

python3-pip CVE-2026-1703 低危 22.0.2+dfsg-1ubuntu0.7 pip: pip: Information disclosure via path traversal when installing crafted wheel archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-02 15:16 修改: 2026-06-17 10:16

libssl3 CVE-2026-45446 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45446

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 10:52

libssl3 CVE-2026-7383 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7383

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 11:02

libssl3 CVE-2026-9076 低危 3.0.2-0ubuntu1.20 3.0.2-0ubuntu1.25 openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9076

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-06-09 17:17 修改: 2026-06-17 11:04

libstdc++6 CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04.2 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2022-03-26 13:15 修改: 2026-06-17 04:37

libcurl4 CVE-2026-8924 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8924

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vim-runtime CVE-2026-25749 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via 'helpfile' option processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25749

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-06 23:15 修改: 2026-06-17 10:25

vim-runtime CVE-2026-26269 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Netbeans specialKeys stack buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26269

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-13 20:17 修改: 2026-06-17 10:26

libcurl4 CVE-2026-9547 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9547

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl CVE-2026-8924 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8924

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libsystemd0 CVE-2023-7008 低危 249.11-0ubuntu3.17 249.11-0ubuntu3.21 systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-7008

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-23 13:15 修改: 2026-06-17 06:51

libsystemd0 CVE-2026-40228 低危 249.11-0ubuntu3.17 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

curl CVE-2026-9547 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9547

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libtasn1-6 CVE-2021-46848 低危 4.18.0-4ubuntu0.1 4.18.0-4ubuntu0.2 libtasn1: Out-of-bound access in ETYPE_OK

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-46848

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2022-10-24 14:15 修改: 2026-06-17 04:15

libtinfo6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-12 15:15 修改: 2026-06-17 06:39

gcc-12-base CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04.2 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2022-03-26 13:15 修改: 2026-06-17 04:37

libgcc-s1 CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04.2 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2022-03-26 13:15 修改: 2026-06-17 04:37

curl CVE-2025-0167 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2025-02-05 10:15 修改: 2026-06-17 08:25

libudev1 CVE-2023-7008 低危 249.11-0ubuntu3.17 249.11-0ubuntu3.21 systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-7008

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-12-23 13:15 修改: 2026-06-17 06:51

libudev1 CVE-2026-40228 低危 249.11-0ubuntu3.17 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:44

libgcrypt20 CVE-2024-2236 低危 1.9.4-3ubuntu3 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2024-03-06 22:15 修改: 2026-06-17 07:24

curl CVE-2025-14524 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:36

curl CVE-2025-15079 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: Host verification bypass during SSH transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:37

libzstd1 CVE-2022-4899 低危 1.4.8+dfsg-3build1 zstd: mysql: buffer overrun in util.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-4899

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-03-31 20:15 修改: 2026-06-17 05:22

curl CVE-2025-15224 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.22 curl: libssh key passphrase bypass without agent set

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-01-08 10:15 修改: 2026-06-17 08:37

ssh CVE-2025-61984 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

ssh CVE-2025-61985 低危 1:8.9p1-3ubuntu0.13 1:8.9p1-3ubuntu0.14 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2025-10-06 19:15 修改: 2026-06-17 09:51

ssh CVE-2026-55654 低危 1:8.9p1-3ubuntu0.13 openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55654

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-06-23 04:17 修改: 2026-06-25 16:59

curl CVE-2026-12064 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12064

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl CVE-2026-3784 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.23 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3784

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-03-11 11:16 修改: 2026-06-17 10:44

curl CVE-2026-4873 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:57

curl CVE-2026-5773 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 10:59

curl CVE-2026-6276 低危 7.81.0-1ubuntu1.21 7.81.0-1ubuntu1.24 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 2026-05-13 13:01 修改: 2026-06-17 11:00

login CVE-2023-29383 低危 1:4.8.1-2ubuntu2.2 shadow: Improper input validation in shadow-utils package utility chfn

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-29383

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2023-04-14 22:15 修改: 2026-06-17 05:49

login CVE-2024-56433 低危 1:4.8.1-2ubuntu2.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:fbb9bbbaf4d2b027acd15252897d5043386eea7121e0e0433e697714bb14beac

发布日期: 2024-12-26 09:15 修改: 2026-06-17 08:12

curl CVE-2026-8286 低危 7.81.0-1ubuntu1.21

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8286

镜像层: sha256:7111ce00d9a8a4e3872593d2dbee47cb429fcd7016ac1ef27c8e599e43e25e1c

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

xxd CVE-2026-25749 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Vim: Arbitrary code execution via 'helpfile' option processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25749

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-06 23:15 修改: 2026-06-17 10:25

xxd CVE-2026-26269 低危 2:8.2.3995-1ubuntu2.24 2:8.2.3995-1ubuntu2.26 vim: Netbeans specialKeys stack buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26269

镜像层: sha256:03bdf99d32f3111b44f8b02ba192a757c161afc95220c8bac85d401e4be8bdd3

发布日期: 2026-02-13 20:17 修改: 2026-06-17 10:26

Java (jar)
低危漏洞:21 中危漏洞:140 高危漏洞:140 严重漏洞:13
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
org.apache.avro:avro CVE-2024-47561 严重 1.11.3 1.11.4 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47561

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-03 11:15 修改: 2026-06-17 07:57

org.apache.avro:avro CVE-2024-47561 严重 1.8.2 1.11.4 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47561

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-03 11:15 修改: 2026-06-17 07:57

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41293 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41293

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41293 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41293

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43512 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43512 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43515 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: tomcat: Improper Authorization allows security bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43515 严重 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: tomcat: Improper Authorization allows security bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.bouncycastle:bcprov-jdk18on CVE-2025-14813 严重 1.78.1 1.80.2, 1.81.1, 1.84 bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14813

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-15 10:16 修改: 2026-06-30 03:16

org.postgresql:postgresql CVE-2024-1597 严重 42.2.16.jre7 42.2.28, 42.3.9, 42.4.4, 42.5.5, 42.6.1, 42.7.2 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-1597

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2024-02-19 13:15 修改: 2026-06-17 07:04

org.springframework.security:spring-security-web CVE-2024-38821 严重 5.7.12 5.7.13, 5.8.15, 6.2.7, 6.0.13, 6.1.11, 6.3.4 Spring-WebFlux: Authorization Bypass of Static Resources in WebFlux Applications

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38821

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-28 07:15 修改: 2026-06-17 07:41

org.springframework.security:spring-security-web CVE-2026-22732 严重 5.7.12 6.5.9, 7.0.4 Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22732

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-19 23:16 修改: 2026-06-17 10:20

org.springframework:spring-web CVE-2016-1000027 严重 5.3.39 6.0.0 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-1000027

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2020-01-02 23:15 修改: 2024-11-21 02:42

com.nimbusds:nimbus-jose-jwt CVE-2023-52428 高危 7.9 9.37.2 nimbus-jose-jwt: large JWE p2c header value causes Denial of Service

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-52428

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-02-11 05:15 修改: 2026-06-17 06:42

commons-io:commons-io CVE-2024-47554 高危 2.11.0 2.14.0 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47554

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-03 12:15 修改: 2026-06-17 07:57

commons-io:commons-io CVE-2024-47554 高危 2.8.0 2.14.0 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47554

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-03 12:15 修改: 2026-06-17 07:57

io.airlift:aircompressor CVE-2024-36114 高危 0.10 0.27 Decompressors can crash the JVM and leak memory content in Aircompressor

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-36114

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-05-29 21:15 修改: 2026-06-17 07:36

io.airlift:aircompressor CVE-2025-67721 高危 0.10 2.0.3 aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67721

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-12 23:15 修改: 2026-06-17 09:58

io.airlift:aircompressor CVE-2025-67721 高危 0.27 2.0.3 aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67721

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-12 23:15 修改: 2026-06-17 09:58

io.netty:netty-codec CVE-2026-42583 高危 4.1.108.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec CVE-2026-42583 高危 4.1.108.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec CVE-2026-42583 高危 4.1.108.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec CVE-2026-42583 高危 4.1.124.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-haproxy CVE-2026-44893 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44893

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-44893 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44893

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-44893 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44893

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-48059 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48059

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-48059 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48059

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-48059 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48059

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-44893 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44893

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-codec-haproxy CVE-2026-48059 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48059

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-http CVE-2026-33870 高危 4.1.108.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http CVE-2026-33870 高危 4.1.108.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http CVE-2026-33870 高危 4.1.108.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http CVE-2026-42584 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42584 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42584 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http CVE-2026-33870 高危 4.1.124.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http CVE-2026-42584 高危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42587 高危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http2 CVE-2025-55163 高危 4.1.108.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-08-13 15:15 修改: 2026-06-17 09:41

io.netty:netty-codec-http2 CVE-2025-55163 高危 4.1.108.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-08-13 15:15 修改: 2026-06-17 09:41

io.netty:netty-codec-http2 CVE-2025-55163 高危 4.1.108.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-08-13 15:15 修改: 2026-06-17 09:41

io.netty:netty-codec-http2 CVE-2026-33871 高危 4.1.108.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http2 CVE-2026-33871 高危 4.1.108.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http2 CVE-2026-33871 高危 4.1.108.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http2 CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http2 CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http2 CVE-2026-42587 高危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-http2 CVE-2026-33871 高危 4.1.124.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-27 20:16 修改: 2026-06-30 03:18

io.netty:netty-codec-http2 CVE-2026-42587 高危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-07-01 13:17

io.netty:netty-codec-redis CVE-2026-44250 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44250

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-codec-redis CVE-2026-44250 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44250

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-codec-redis CVE-2026-44250 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44250

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-codec-redis CVE-2026-44890 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44890

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-44890 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44890

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-44890 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44890

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-48006 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48006

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-48006 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48006

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-48006 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48006

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-50011 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty: Denial of Service via malicious Redis array header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50011

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-50011 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty: Denial of Service via malicious Redis array header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50011

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-50011 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty: Denial of Service via malicious Redis array header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50011

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-44250 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44250

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-codec-redis CVE-2026-44890 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44890

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-48006 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48006

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-redis CVE-2026-50011 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-redis: Netty: Denial of Service via malicious Redis array header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50011

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-smtp CVE-2025-59419 高危 4.1.108.Final 4.2.7.Final, 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-15 16:15 修改: 2026-06-17 09:46

io.netty:netty-codec-smtp CVE-2025-59419 高危 4.1.108.Final 4.2.7.Final, 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-15 16:15 修改: 2026-06-17 09:46

io.netty:netty-codec-smtp CVE-2025-59419 高危 4.1.108.Final 4.2.7.Final, 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-15 16:15 修改: 2026-06-17 09:46

io.netty:netty-codec-smtp CVE-2025-59419 高危 4.1.124.Final 4.2.7.Final, 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-15 16:15 修改: 2026-06-17 09:46

io.netty:netty-handler CVE-2025-24970 高危 4.1.108.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24970

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 08:59

io.netty:netty-handler CVE-2025-24970 高危 4.1.108.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24970

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 08:59

io.netty:netty-handler CVE-2025-24970 高危 4.1.108.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24970

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 08:59

io.netty:netty-handler CVE-2026-44249 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-handler CVE-2026-44249 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-handler CVE-2026-44249 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-handler CVE-2026-45416 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-45416 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-45416 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-50010 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-50010 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-50010 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-44249 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-11 22:16 修改: 2026-06-30 03:19

io.netty:netty-handler CVE-2026-45416 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-handler CVE-2026-50010 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-45674 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-45674 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-45674 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-47691 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-47691 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-47691 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-45674 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-resolver-dns CVE-2026-47691 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-transport-sctp CVE-2026-46340 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46340

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-transport-sctp CVE-2026-46340 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46340

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-transport-sctp CVE-2026-46340 高危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46340

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

io.netty:netty-transport-sctp CVE-2026-46340 高危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46340

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-30 03:20

com.fasterxml.jackson.core:jackson-core CVE-2025-52999 高危 2.12.7 2.15.0 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52999

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-06-25 17:15 修改: 2026-06-17 09:37

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.12.7.1 2.18.8, 3.1.4, 2.21.4 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

org.apache.avro:avro CVE-2023-39410 高危 1.8.2 1.11.3 apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-39410

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2023-09-29 17:15 修改: 2026-06-17 06:12

org.apache.hive:hive-service CVE-2024-23945 高危 3.1.3 4.0.0 Apache Hive and Spark: CookieSigner exposes the correct signature when message verification fails

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23945

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-23 16:15 修改: 2026-06-17 07:13

org.apache.thrift:libthrift CVE-2026-43869 高危 0.14.0 0.23.0 Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43869

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-05 08:16 修改: 2026-07-01 13:17

org.apache.thrift:libthrift CVE-2026-43869 高危 0.14.0 0.23.0 Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43869

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-05 08:16 修改: 2026-07-01 13:17

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.12.7.1 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-30 03:21

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.17.0 2.18.8, 3.1.4, 2.21.4 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.17.0 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-30 03:21

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.17.2 2.18.8, 3.1.4, 2.21.4 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.17.2 2.18.8, 3.1.4, 2.21.4 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.17.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-30 03:21

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24734 高危 9.0.113 11.0.18, 10.1.52, 9.0.115 tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24734

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-17 19:21 修改: 2026-06-30 03:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24734 高危 9.0.113 11.0.18, 10.1.52, 9.0.115 tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24734

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-17 19:21 修改: 2026-06-30 03:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24880 高危 9.0.113 9.0.116, 10.1.52, 11.0.20 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24880

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:23

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24880 高危 9.0.113 9.0.116, 10.1.52, 11.0.20 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24880

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:23

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-34483 高危 9.0.113 9.0.116, 10.1.54, 11.0.21 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34483

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:39

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-34483 高危 9.0.113 9.0.116, 10.1.54, 11.0.21 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34483

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:39

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41284 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 Allocation of Resources Without Limits or Throttling vulnerability in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41284

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41284 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 Allocation of Resources Without Limits or Throttling vulnerability in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41284

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-42498 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42498

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:47

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-42498 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42498

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:47

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43513 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43513 高危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.zookeeper:zookeeper CVE-2026-24281 高危 3.8.4 3.8.6, 3.9.5 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24281

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-07 09:16 修改: 2026-06-30 03:17

org.apache.zookeeper:zookeeper CVE-2026-24308 高危 3.8.4 3.9.5, 3.8.6 Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24308

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-07 09:16 修改: 2026-06-30 03:17

org.apache.zookeeper:zookeeper CVE-2024-51504 高危 3.9.2 3.9.3 org.apache.zookeeper: Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-51504

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-11-07 10:15 修改: 2026-06-17 08:05

org.apache.zookeeper:zookeeper CVE-2026-24281 高危 3.9.2 3.8.6, 3.9.5 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24281

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-07 09:16 修改: 2026-06-30 03:17

org.apache.zookeeper:zookeeper CVE-2026-24308 高危 3.9.2 3.9.5, 3.8.6 Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24308

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-07 09:16 修改: 2026-06-30 03:17

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.17.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-30 03:21

org.eclipse.jetty.http2:http2-common CVE-2024-22201 高危 9.4.53.v20231009 9.4.54, 10.0.20, 11.0.20 jetty: stop accepting new connections from valid clients

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-22201

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-02-26 16:27 修改: 2026-06-17 07:10

org.eclipse.jetty.http2:http2-common CVE-2025-5115 高危 9.4.53.v20231009 9.4.58, 10.0.26, 11.0.26 jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5115

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-08-20 20:15 修改: 2026-06-17 09:47

org.eclipse.jetty:jetty-http CVE-2026-2332 高危 9.4.57.v20241219 12.1.7, 12.0.33 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-14 12:16 修改: 2026-06-30 03:18

org.jline:jline-remote-telnet GHSA-2r2c-cx56-8933 高危 3.9.0 4.2.1 JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

漏洞详情: https://github.com/advisories/GHSA-2r2c-cx56-8933

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-18 13:07 修改: 2026-06-18 13:07

org.jline:jline-remote-telnet GHSA-2r2c-cx56-8933 高危 3.9.0 4.2.1 JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

漏洞详情: https://github.com/advisories/GHSA-2r2c-cx56-8933

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-18 13:07 修改: 2026-06-18 13:07

org.jline:jline-remote-telnet GHSA-47qp-hqvx-6r3f 高危 3.9.0 4.2.1 JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

漏洞详情: https://github.com/advisories/GHSA-47qp-hqvx-6r3f

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-18 13:07 修改: 2026-06-18 13:07

org.jline:jline-remote-telnet GHSA-47qp-hqvx-6r3f 高危 3.9.0 4.2.1 JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

漏洞详情: https://github.com/advisories/GHSA-47qp-hqvx-6r3f

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-18 13:07 修改: 2026-06-18 13:07

org.lz4:lz4-java CVE-2025-12183 高危 1.8.0 1.8.1 lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12183

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-11-28 16:15 修改: 2026-06-17 08:31

org.lz4:lz4-java CVE-2025-66566 高危 1.8.0 lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66566

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-05 18:15 修改: 2026-06-17 09:57

com.google.protobuf:protobuf-java CVE-2021-22569 高危 2.5.0 3.16.1, 3.18.2, 3.19.2 protobuf-java: potential DoS in the parsing procedure for binary data

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-22569

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-01-10 14:10 修改: 2026-06-17 03:37

org.postgresql:postgresql CVE-2022-21724 高危 42.2.16.jre7 42.2.25, 42.3.2 jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-21724

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2022-02-02 12:15 修改: 2026-06-17 04:26

org.postgresql:postgresql CVE-2022-31197 高危 42.2.16.jre7 42.2.26, 42.4.1, 42.3.7 postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-31197

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2022-08-03 19:15 修改: 2026-06-17 04:45

org.postgresql:postgresql CVE-2026-42198 高危 42.2.16.jre7 42.7.11 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42198

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2026-04-29 16:16 修改: 2026-06-30 03:19

org.springframework.security:spring-security-crypto CVE-2025-22228 高危 5.7.12 6.3.8, 6.4.4, 6.2.10, 6.1.14, 6.0.16, 5.8.18, 5.7.16 spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22228

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-03-20 06:15 修改: 2026-06-17 08:45

com.google.protobuf:protobuf-java CVE-2021-22569 高危 2.5.0 3.16.1, 3.18.2, 3.19.2 protobuf-java: potential DoS in the parsing procedure for binary data

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-22569

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-01-10 14:10 修改: 2026-06-17 03:37

com.google.protobuf:protobuf-java CVE-2024-7254 高危 2.5.0 3.25.5, 4.27.5, 4.28.2 protobuf: StackOverflow vulnerability in Protocol Buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-09-19 01:15 修改: 2026-06-17 08:19

org.springframework:spring-core CVE-2025-41249 高危 5.3.39 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-41249

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-16 11:15 修改: 2026-06-17 09:22

com.google.protobuf:protobuf-java CVE-2024-7254 高危 2.5.0 3.25.5, 4.27.5, 4.28.2 protobuf: StackOverflow vulnerability in Protocol Buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-09-19 01:15 修改: 2026-06-17 08:19

com.nimbusds:nimbus-jose-jwt CVE-2025-53864 中危 7.9 10.0.2, 9.37.4 com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39

com.nimbusds:nimbus-jose-jwt CVE-2025-53864 中危 9.37.2 10.0.2, 9.37.4 com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.12.7.1 2.18.8, 2.21.4, 3.1.4 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.12.7.1 3.1.4, 2.18.9, 2.21.5, 2.22.1 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-29 13:38

io.netty:netty-common CVE-2024-47535 中危 4.1.108.Final 4.1.115.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-11-12 16:15 修改: 2026-06-17 07:57

io.netty:netty-common CVE-2024-47535 中危 4.1.108.Final 4.1.115.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-11-12 16:15 修改: 2026-06-17 07:57

io.netty:netty-common CVE-2024-47535 中危 4.1.108.Final 4.1.115.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-11-12 16:15 修改: 2026-06-17 07:57

io.netty:netty-common CVE-2025-25193 中危 4.1.108.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-25193

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 09:00

io.netty:netty-common CVE-2025-25193 中危 4.1.108.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-25193

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 09:00

io.netty:netty-common CVE-2025-25193 中危 4.1.108.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-25193

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-02-10 22:15 修改: 2026-06-17 09:00

commons-lang:commons-lang CVE-2025-48924 中危 2.6 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

io.netty:netty-codec-http CVE-2025-67735 中危 4.1.108.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-16 01:15 修改: 2026-06-17 09:58

io.netty:netty-codec-http CVE-2025-67735 中危 4.1.108.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-16 01:15 修改: 2026-06-17 09:58

io.netty:netty-codec-http CVE-2025-67735 中危 4.1.108.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-16 01:15 修改: 2026-06-17 09:58

io.netty:netty-codec-http CVE-2026-41417 中危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-06 22:16 修改: 2026-06-17 10:46

io.netty:netty-codec-http CVE-2026-41417 中危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-06 22:16 修改: 2026-06-17 10:46

io.netty:netty-codec-http CVE-2026-41417 中危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-06 22:16 修改: 2026-06-17 10:46

io.netty:netty-codec-http CVE-2026-42580 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: Request smuggling via chunk size parser integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42580 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: Request smuggling via chunk size parser integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42580 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: Netty: Request smuggling via chunk size parser integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42581 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42581 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42581 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42585 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42585 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42585 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-50020 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50020

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

io.netty:netty-codec-http CVE-2026-50020 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50020

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

io.netty:netty-codec-http CVE-2026-50020 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50020

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

commons-lang:commons-lang CVE-2025-48924 中危 2.6 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

commons-lang:commons-lang CVE-2025-48924 中危 2.6 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

io.netty:netty-resolver-dns CVE-2026-45673 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-resolver-dns CVE-2026-45673 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-resolver-dns CVE-2026-45673 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

commons-net:commons-net CVE-2021-37533 中危 3.1 3.9.0 apache-commons-net: FTP client trusts the host from PASV response by default

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-37533

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-12-03 15:15 修改: 2026-06-17 04:00

io.netty:netty-codec-http CVE-2025-67735 中危 4.1.124.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-16 01:15 修改: 2026-06-17 09:58

io.netty:netty-resolver-dns CVE-2026-45673 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.118.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-epoll CVE-2026-45536 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-kqueue CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-kqueue CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-kqueue CVE-2026-45536 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-kqueue CVE-2026-45536 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-transport-native-kqueue CVE-2026-45536 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-codec-http CVE-2026-41417 中危 4.1.124.Final 4.1.133.Final, 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-06 22:16 修改: 2026-06-17 10:46

io.netty:netty-codec-http CVE-2026-42580 中危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: Netty: Request smuggling via chunk size parser integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-http CVE-2026-42581 中危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-http CVE-2026-42585 中危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.opentelemetry:opentelemetry-api CVE-2026-45292 中危 1.40.0 1.62.0 opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45292

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-28 17:16 修改: 2026-07-01 13:17

io.netty:netty-codec-http CVE-2026-50020 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50020

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

ch.qos.logback:logback-core CVE-2025-11226 中危 1.3.14 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11226

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-01 08:15 修改: 2026-06-25 17:16

ch.qos.logback:logback-core CVE-2024-12798 中危 1.3.14 1.5.13, 1.3.15 logback-core: arbitrary code execution via JaninoEventEvaluator

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12798

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-19 16:15 修改: 2026-06-17 07:00

org.apache.commons:commons-compress CVE-2024-25710 中危 1.21 1.26.0 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-25710

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-02-19 09:15 修改: 2026-06-17 07:16

org.apache.commons:commons-compress CVE-2024-26308 中危 1.21 1.26.0 commons-compress: OutOfMemoryError unpacking broken Pack200 file

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26308

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-02-19 09:15 修改: 2026-06-17 07:17

org.apache.commons:commons-configuration2 CVE-2026-45205 中危 2.10.1 2.15.0 Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51

org.apache.commons:commons-configuration2 CVE-2024-29131 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29131

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2024-29131 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29131

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2024-29131 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29131

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2024-29133 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29133

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2024-29133 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29133

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2024-29133 中危 2.8.0 2.10.1 commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29133

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-03-21 09:15 修改: 2026-06-17 07:22

org.apache.commons:commons-configuration2 CVE-2026-45205 中危 2.8.0 2.15.0 Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51

org.apache.commons:commons-configuration2 CVE-2026-45205 中危 2.8.0 2.15.0 Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51

org.apache.commons:commons-configuration2 CVE-2026-45205 中危 2.8.0 2.15.0 Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51

org.apache.commons:commons-lang3 CVE-2025-48924 中危 3.17.0 3.18.0 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

org.apache.commons:commons-lang3 CVE-2025-48924 中危 3.9 3.18.0 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

org.apache.commons:commons-lang3 CVE-2025-48924 中危 3.9 3.18.0 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30

org.apache.hive:hive-exec CVE-2024-29869 中危 3.1.3 4.0.1 Apache Hive Incorrectly Assigns Permissions for a Critical Resource

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29869

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-01-28 22:15 修改: 2026-06-17 07:23

org.apache.hive:hive-llap-common CVE-2024-23953 中危 3.1.3 4.0.0 Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23953

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-01-28 09:15 修改: 2026-06-17 07:13

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.17.0 2.18.8, 2.21.4, 3.1.4 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

org.apache.poi:poi-ooxml CVE-2025-31672 中危 5.2.2 5.4.0 org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-31672

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-04-09 12:15 修改: 2026-06-17 09:10

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.17.0 3.1.4, 2.18.9, 2.21.5, 2.22.1 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-29 13:38

com.fasterxml.jackson.core:jackson-core CVE-2025-49128 中危 2.12.7 2.13.0 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49128

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-06-06 22:15 修改: 2026-06-17 09:30

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.12.7 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

io.netty:netty-codec CVE-2025-58057 中危 4.1.108.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-04 10:42 修改: 2026-06-17 09:43

io.netty:netty-codec CVE-2025-58057 中危 4.1.108.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-04 10:42 修改: 2026-06-17 09:43

io.netty:netty-codec CVE-2025-58057 中危 4.1.108.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-04 10:42 修改: 2026-06-17 09:43

io.netty:netty-codec-http2 CVE-2026-47244 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47244

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:54

io.netty:netty-codec-http2 CVE-2026-47244 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47244

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:54

io.netty:netty-codec-http2 CVE-2026-47244 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47244

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:54

io.netty:netty-codec-http2 CVE-2026-48043 中危 4.1.108.Final 4.1.135.Final, 4.2.15.Final netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48043

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-http2 CVE-2026-48043 中危 4.1.108.Final 4.1.135.Final, 4.2.15.Final netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48043

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-http2 CVE-2026-48043 中危 4.1.108.Final 4.1.135.Final, 4.2.15.Final netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48043

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-http2 CVE-2026-50560 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50560

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

io.netty:netty-codec-http2 CVE-2026-50560 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50560

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

io.netty:netty-codec-http2 CVE-2026-50560 中危 4.1.108.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50560

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.17.0 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

io.netty:netty-codec CVE-2025-58057 中危 4.1.124.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-04 10:42 修改: 2026-06-17 09:43

io.netty:netty-codec-http2 CVE-2026-47244 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47244

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:54

io.netty:netty-codec-http2 CVE-2026-48043 中危 4.1.124.Final 4.1.135.Final, 4.2.15.Final netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48043

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-30 03:20

io.netty:netty-codec-http2 CVE-2026-50560 中危 4.1.124.Final 4.2.15.Final, 4.1.135.Final netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50560

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-25854 中危 9.0.113 9.0.116, 10.1.53, 11.0.20 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25854

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:25

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-25854 中危 9.0.113 9.0.116, 10.1.53, 11.0.20 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25854

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:25

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-32990 中危 9.0.113 9.0.116, 10.1.53, 11.0.20 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32990

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:36

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-32990 中危 9.0.113 9.0.116, 10.1.53, 11.0.20 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32990

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-09 20:16 修改: 2026-06-17 10:36

io.netty:netty-codec-mqtt CVE-2026-44248 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-mqtt CVE-2026-44248 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-mqtt CVE-2026-44248 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-codec-mqtt CVE-2026-44248 中危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.17.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

org.apache.zookeeper:zookeeper CVE-2025-58457 中危 3.9.2 3.9.4 org.apache.zookeeper/zookeeper: Apache ZooKeeper: Insufficient Permission Check

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58457

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-24 10:15 修改: 2026-06-17 09:44

org.bouncycastle:bcpkix-jdk18on CVE-2026-5588 中危 1.79 1.84 bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5588

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-15 10:16 修改: 2026-06-30 03:21

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.17.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

org.bouncycastle:bcprov-jdk18on CVE-2026-0636 中危 1.78.1 1.84 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0636

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-15 10:16 修改: 2026-06-30 03:17

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.17.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.17.2 3.1.4, 2.18.9, 2.21.5, 2.22.1 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-29 13:38

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.17.2 3.1.4, 2.18.9, 2.21.5, 2.22.1 jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-29 13:38

org.eclipse.jetty:jetty-http CVE-2024-6763 中危 9.4.57.v20241219 12.0.12 org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18

org.elasticsearch:elasticsearch CVE-2024-52980 中危 7.17.29 8.15.1 Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52980

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-04-08 17:15 修改: 2026-06-17 08:07

org.elasticsearch:elasticsearch CVE-2024-52980 中危 7.17.29 8.15.1 Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52980

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-04-08 17:15 修改: 2026-06-17 08:07

org.elasticsearch:elasticsearch CVE-2025-37727 中危 7.17.29 8.18.8, 8.19.5, 9.0.8, 9.1.5 org.elasticsearch/elasticsearch-core: Elasticsearch Insertion of sensitive information in log file

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-37727

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-10 10:15 修改: 2026-06-17 09:15

org.elasticsearch:elasticsearch CVE-2025-37727 中危 7.17.29 8.18.8, 8.19.5, 9.0.8, 9.1.5 org.elasticsearch/elasticsearch-core: Elasticsearch Insertion of sensitive information in log file

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-37727

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-10 10:15 修改: 2026-06-17 09:15

org.elasticsearch:elasticsearch CVE-2025-37731 中危 7.17.29 8.19.8, 9.1.8, 9.2.2 elasticsearch: Elasticsearch: User impersonation due to improper authentication in Public Key Infrastructure (PKI) realm

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-37731

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-15 11:15 修改: 2026-06-17 09:15

org.elasticsearch:elasticsearch CVE-2025-37731 中危 7.17.29 8.19.8, 9.1.8, 9.2.2 elasticsearch: Elasticsearch: User impersonation due to improper authentication in Public Key Infrastructure (PKI) realm

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-37731

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-12-15 11:15 修改: 2026-06-17 09:15

com.fasterxml.woodstox:woodstox-core CVE-2022-40152 中危 5.3.0 6.4.0, 5.4.0 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40152

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-09-16 10:15 修改: 2026-06-17 05:01

com.google.guava:guava CVE-2018-10237 中危 11.0.2 24.1.1-android guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-10237

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2018-04-26 21:29 修改: 2026-06-17 01:33

com.google.guava:guava CVE-2023-2976 中危 11.0.2 32.0.0-android guava: insecure temporary directory creation

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-2976

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2023-06-14 18:15 修改: 2026-06-17 05:53

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.17.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.17.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

ch.qos.logback:logback-core CVE-2024-12798 中危 1.3.14 1.5.13, 1.3.15 logback-core: arbitrary code execution via JaninoEventEvaluator

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12798

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-19 16:15 修改: 2026-06-17 07:00

ch.qos.logback:logback-core CVE-2025-11226 中危 1.3.14 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11226

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-10-01 08:15 修改: 2026-06-25 17:16

io.netty:netty-codec-redis CVE-2026-42586 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-redis CVE-2026-42586 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-redis CVE-2026-42586 中危 4.1.108.Final 4.2.13.Final, 4.1.133.Final netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

org.postgresql:postgresql CVE-2022-41946 中危 42.2.16.jre7 42.2.27, 42.3.8, 42.4.3, 42.5.1 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-41946

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2022-11-23 20:15 修改: 2026-06-17 05:04

org.postgresql:postgresql GHSA-673j-qm5f-xpv8 中危 42.2.16.jre7 42.3.3 pgjdbc Arbitrary File Write Vulnerability

漏洞详情: https://github.com/advisories/GHSA-673j-qm5f-xpv8

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2022-02-16 00:08 修改: 2024-01-22 19:35

org.springframework.security:spring-security-core CVE-2024-38827 中危 5.7.12 5.7.14, 5.8.16, 6.0.14, 6.1.12, 6.2.8, 6.3.5 spring-security: authorization bypass for case sensitive comparisons

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38827

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-02 15:15 修改: 2026-06-17 07:41

com.google.protobuf:protobuf-java CVE-2022-3171 中危 2.5.0 3.21.7, 3.20.3, 3.19.6, 3.16.3 protobuf-java: timeout in parser leads to DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3171

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-10-12 23:15 修改: 2026-06-17 04:58

com.google.protobuf:protobuf-java CVE-2022-3171 中危 2.5.0 3.21.7, 3.20.3, 3.19.6, 3.16.3 protobuf-java: timeout in parser leads to DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3171

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2022-10-12 23:15 修改: 2026-06-17 04:58

com.nimbusds:nimbus-jose-jwt CVE-2025-53864 中危 10.0.1 10.0.2, 9.37.4 com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39

org.springframework.security:spring-security-web CVE-2026-47838 中危 5.7.12 6.5.11 Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47838

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-10 00:16 修改: 2026-06-30 22:16

org.springframework:spring-context CVE-2024-38820 中危 5.3.39 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38820

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-18 06:15 修改: 2026-06-17 07:41

com.fasterxml.jackson.core:jackson-databind CVE-2026-50193 中危 2.12.7.1 2.14.0 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50193

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:05

io.netty:netty-codec-redis CVE-2026-42586 中危 4.1.124.Final 4.2.13.Final, 4.1.133.Final netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

org.springframework:spring-web CVE-2024-38820 中危 5.3.39 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38820

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-10-18 06:15 修改: 2026-06-17 07:41

ch.qos.logback:logback-core CVE-2024-12801 低危 1.3.14 1.5.13, 1.3.15 logback-core: SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12801

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-19 17:15 修改: 2026-06-17 07:00

ch.qos.logback:logback-core CVE-2026-1225 低危 1.3.14 1.5.25 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1225

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-01-22 10:16 修改: 2026-06-17 10:15

io.netty:netty-handler-proxy CVE-2026-42578 低危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-handler-proxy CVE-2026-42578 低危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-handler-proxy CVE-2026-42578 低危 4.1.108.Final 4.1.133.Final, 4.2.13.Final netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

io.netty:netty-handler-proxy CVE-2026-42578 低危 4.1.124.Final 4.1.133.Final, 4.2.13.Final netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-13 19:17 修改: 2026-06-30 03:19

com.google.guava:guava CVE-2020-8908 低危 11.0.2 32.0.0-android guava: local information disclosure via temporary directory created with unsafe permissions

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-8908

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2020-12-10 23:15 修改: 2026-06-17 03:27

commons-configuration:commons-configuration CVE-2025-46392 低危 1.6 apache-commons-configuration: Apache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.x

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-46392

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-05-09 10:15 修改: 2026-06-17 09:26

org.eclipse.jetty:jetty-http CVE-2025-11143 低危 9.4.57.v20241219 12.0.31, 12.1.5 org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11143

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-03-05 10:15 修改: 2026-06-17 08:29

org.postgresql:postgresql CVE-2022-26520 低危 42.2.16.jre7 42.3.3 postgresql-jdbc: Arbitrary File Write Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-26520

镜像层: sha256:05c16fc4559c40c8b309c2f90a134938bc3381ccca5fff83f664557d6d7f9469

发布日期: 2022-03-10 17:47 修改: 2026-06-17 04:35

ch.qos.logback:logback-core CVE-2026-1225 低危 1.3.14 1.5.25 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1225

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-01-22 10:16 修改: 2026-06-17 10:15

org.springframework.security:spring-security-core CVE-2026-22746 低危 5.7.12 6.5.10, 7.0.5 Spring Security: Spring Security: Timing attack defense bypass allows information disclosure

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22746

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-04-22 06:16 修改: 2026-06-17 10:20

ch.qos.logback:logback-core CVE-2024-12801 低危 1.3.14 1.5.13, 1.3.15 logback-core: SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12801

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-12-19 17:15 修改: 2026-06-17 07:00

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43514 低危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43514 低危 9.0.113 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43514

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

io.netty:netty-codec-http CVE-2025-58056 低危 4.1.108.Final 4.1.125.Final, 4.2.5.Final netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-03 21:15 修改: 2026-06-17 09:43

org.apache.hadoop:hadoop-common CVE-2024-23454 低危 2.10.2 3.4.0 Apache Hadoop: Temporary File Local Information Disclosure

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23454

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2024-09-25 08:15 修改: 2026-06-17 07:12

org.springframework:spring-context CVE-2025-22233 低危 5.3.39 6.2.7, 6.1.20 CVE-2024-38820 ensured Locale-independent, lowercase conversion for bo ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22233

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-05-16 20:15 修改: 2026-06-17 08:45

io.netty:netty-codec-http CVE-2025-58056 低危 4.1.108.Final 4.1.125.Final, 4.2.5.Final netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-03 21:15 修改: 2026-06-17 09:43

io.netty:netty-codec-http CVE-2025-58056 低危 4.1.108.Final 4.1.125.Final, 4.2.5.Final netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-03 21:15 修改: 2026-06-17 09:43

io.netty:netty-codec-http CVE-2025-58056 低危 4.1.124.Final 4.1.125.Final, 4.2.5.Final netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056

镜像层: sha256:a2b98b9243c22e1314872215247ff1696aceff113a8f060412a1a39618bd0853

发布日期: 2025-09-03 21:15 修改: 2026-06-17 09:43

Node.js (node-pkg)
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
Python (python-pkg)
低危漏洞:0 中危漏洞:2 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
urllib3 CVE-2026-44431 高危 2.6.3 2.7.0 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44431

镜像层: sha256:a4f7897d41a5bcc0d0328497734b2f894fbd42a0de8f09ffab4258c082f8fe9a

发布日期: 2026-05-13 16:16 修改: 2026-06-26 12:16

urllib3 CVE-2026-44432 高危 2.6.3 2.7.0 urllib3: urllib3: Denial of Service due to excessive HTTP response decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44432

镜像层: sha256:a4f7897d41a5bcc0d0328497734b2f894fbd42a0de8f09ffab4258c082f8fe9a

发布日期: 2026-05-13 16:16 修改: 2026-07-01 13:17

idna CVE-2026-45409 中危 3.11 3.15 Internationalized Domain Names in Applications (IDNA) for Python provi ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45409

镜像层: sha256:a4f7897d41a5bcc0d0328497734b2f894fbd42a0de8f09ffab4258c082f8fe9a

发布日期: 2026-06-05 23:16 修改: 2026-06-17 10:52

requests CVE-2026-25645 中危 2.32.5 2.33.0 requests: Requests: Security bypass due to predictable temporary file creation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25645

镜像层: sha256:a4f7897d41a5bcc0d0328497734b2f894fbd42a0de8f09ffab4258c082f8fe9a

发布日期: 2026-03-25 17:16 修改: 2026-06-17 10:25

/etc/ssh/ssh_host_ecdsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_ed25519_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_rsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×