docker.io/georgx22/mcp-office-docs:latest linux/arm64

docker.io/georgx22/mcp-office-docs:latest - Trivy安全扫描结果 扫描时间: 2026-09-18 16:20 温馨提示: 这是一个 linux/arm64 系统架构镜像
全部漏洞信息
低危漏洞:2 中危漏洞:11 高危漏洞:7 严重漏洞:0

系统OS: alpine 3.24.1 扫描引擎: Trivy 扫描时间: 2026-09-18 16:20

docker.io/georgx22/mcp-office-docs:latest (alpine 3.24.1) (alpine)
低危漏洞:0 中危漏洞:1 高危漏洞:7 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
libuuid CVE-2026-53612 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53612

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid CVE-2026-53613 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53613

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid CVE-2026-53614 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53614

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid CVE-2026-76642 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-76642

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-09-03 13:06 修改: 2026-09-03 15:17

libuuid CVE-2026-78408 高危 2.42.1-r0 2.42.3-r1 util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-78408

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-09-02 16:17 修改: 2026-09-05 14:17

libuuid CVE-2026-78409 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-78409

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-09-02 16:17 修改: 2026-09-03 18:12

libuuid CVE-2026-78410 高危 2.42.1-r0 2.42.3-r0 util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-78410

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-09-02 16:17 修改: 2026-09-04 19:17

libuuid CVE-2026-27456 中危 2.42.1-r0 2.42.3-r0 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-04-03 22:16 修改: 2026-07-24 22:10

Python (python-pkg)
低危漏洞:2 中危漏洞:10 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
pip CVE-2025-8869 中危 25.0.1 25.3 pip: pip missing checks on symbolic link extraction

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8869

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2025-09-24 15:15 修改: 2026-06-17 10:07

pip CVE-2025-8869 中危 25.0.1 25.3 pip: pip missing checks on symbolic link extraction

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8869

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2025-09-24 15:15 修改: 2026-06-17 10:07

pip CVE-2026-13346 中危 25.0.1 26.2.0 pip: pip: Arbitrary file installation via malicious package indexes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13346

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2026-07-29 19:16 修改: 2026-08-20 13:17

pip CVE-2026-13346 中危 25.0.1 26.2.0 pip: pip: Arbitrary file installation via malicious package indexes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13346

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-07-29 19:16 修改: 2026-08-20 13:17

pip CVE-2026-3219 中危 25.0.1 26.1 pip: pip: Incorrect file installation due to improper archive handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3219

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2026-04-20 16:16 修改: 2026-06-17 10:43

pip CVE-2026-3219 中危 25.0.1 26.1 pip: pip: Incorrect file installation due to improper archive handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3219

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-04-20 16:16 修改: 2026-06-17 10:43

pip CVE-2026-6357 中危 25.0.1 26.1 pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6357

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2026-04-27 15:16 修改: 2026-06-17 11:00

pip CVE-2026-6357 中危 25.0.1 26.1 pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6357

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-04-27 15:16 修改: 2026-06-17 11:00

pip CVE-2026-8643 中危 25.0.1 26.1.2 python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8643

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2026-06-01 17:17 修改: 2026-09-16 13:18

pip CVE-2026-8643 中危 25.0.1 26.1.2 python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8643

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-06-01 17:17 修改: 2026-09-16 13:18

pip CVE-2026-1703 低危 25.0.1 26.0 pip: pip: Information disclosure via path traversal when installing crafted wheel archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703

镜像层: sha256:1bfee85ec864349b901b6c41f8e3d851da749e7f7cb49565fea7aaaa62a693b5

发布日期: 2026-02-02 15:16 修改: 2026-06-17 10:16

pip CVE-2026-1703 低危 25.0.1 26.0 pip: pip: Information disclosure via path traversal when installing crafted wheel archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703

镜像层: sha256:b9945c83d074bea006fc7e070eb40ff7514cce66c533aa5d8e3fe1d902654c15

发布日期: 2026-02-02 15:16 修改: 2026-06-17 10:16

检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×