docker.io/gvenzl/oracle-xe:18.4.0 linux/amd64

docker.io/gvenzl/oracle-xe:18.4.0 - Trivy安全扫描结果 扫描时间: 2026-06-23 19:36
全部漏洞信息
低危漏洞:2 中危漏洞:91 高危漏洞:55 严重漏洞:1

系统OS: oracle 8.10 扫描引擎: Trivy 扫描时间: 2026-06-23 19:36

docker.io/gvenzl/oracle-xe:18.4.0 (oracle 8.10) (oracle)
低危漏洞:1 中危漏洞:68 高危漏洞:35 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
brotli CVE-2025-6176 高危 1.0.6-3.el8 1.0.6-4.el8_10 Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6176

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-10-31 00:15 修改: 2026-04-15 00:35

expat CVE-2025-59375 高危 2.2.5-15.0.1.el8_10 2.5.0-1.el8_10 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59375

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-09-15 03:15 修改: 2026-05-12 13:17

expat CVE-2026-45186 高危 2.2.5-15.0.1.el8_10 2.5.0-2.el8_10 libexpat: denial of service via crafted XML input

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45186

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-10 07:16 修改: 2026-05-14 17:20

gnupg2 CVE-2025-68973 高危 2.2.20-3.el8_6 2.2.20-4.el8_10 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-28 17:16 修改: 2026-01-14 19:16

gnutls CVE-2026-33845 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33845

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

gnutls CVE-2026-33846 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33846

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-04 10:15 修改: 2026-06-02 16:16

gnutls CVE-2026-3833 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3833

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42009 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42009

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-18 13:16 修改: 2026-06-08 17:16

gnutls CVE-2026-42010 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Authentication Bypass via NUL Character in Username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42010

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-07 12:16 修改: 2026-06-10 16:17

gnutls CVE-2026-42011 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Security bypass due to incorrect name constraint handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42011

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-07 15:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42012 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42012

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42013 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42013

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42014 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42014

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-06-16 02:16 修改: 2026-06-16 15:26

gnutls CVE-2026-42015 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42015

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

gnutls CVE-2026-5260 高危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.6 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5260

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

krb5-libs CVE-2024-3596 高危 1.18.2-29.0.1.el8_10 1.18.2-30.0.1.el8_10 freeradius: forgery attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-3596

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-07-09 12:15 修改: 2026-05-12 12:16

krb5-libs CVE-2026-40355 高危 1.18.2-29.0.1.el8_10 1.18.2-34.0.1.el8_10 krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40355

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-04-28 06:16 修改: 2026-04-28 20:11

krb5-libs CVE-2026-40356 高危 1.18.2-29.0.1.el8_10 1.18.2-34.0.1.el8_10 krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40356

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-04-28 07:16 修改: 2026-04-28 20:11

libarchive CVE-2025-5914 高危 3.3.3-5.el8 3.3.3-6.el8_10 libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5914

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-09 20:15 修改: 2026-02-05 20:15

libarchive CVE-2026-4424 高危 3.3.3-5.el8 3.3.3-7.el8_10 libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4424

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-19 15:16 修改: 2026-06-10 18:17

libarchive CVE-2026-5121 高危 3.3.3-5.el8 3.3.3-7.el8_10 libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5121

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 08:16 修改: 2026-06-10 18:17

libcap CVE-2026-4878 高危 2.48-6.el8_9 2.48-6.el8_10.1 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4878

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-04-09 16:16 修改: 2026-06-11 10:16

libnghttp2 CVE-2026-27135 高危 1.33.0-6.el8_10.1 1.33.0-6.el8_10.2 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27135

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-18 18:16 修改: 2026-05-13 22:16

libxml2 CVE-2024-56171 高危 2.9.7-18.el8_10.1 2.9.7-19.el8_10 libxml2: Use-After-Free in libxml2

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56171

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-02-18 22:15 修改: 2025-11-03 21:17

libxml2 CVE-2025-24928 高危 2.9.7-18.el8_10.1 2.9.7-19.el8_10 libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24928

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-02-18 23:15 修改: 2025-11-03 22:18

libxml2 CVE-2025-49794 高危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.1 libxml: Heap use after free (UAF) leads to Denial of service (DoS)

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49794

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-16 16:15 修改: 2026-06-02 14:16

libxml2 CVE-2025-49796 高危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.1 libxml: Type confusion leads to Denial of service (DoS)

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49796

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-16 16:15 修改: 2026-06-02 14:16

libxml2 CVE-2025-6021 高危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.1 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6021

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-12 13:15 修改: 2026-05-12 13:17

libxml2 CVE-2025-7425 高危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.2 libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-7425

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-10 14:15 修改: 2026-05-12 13:17

openssl-libs CVE-2024-4741 高危 1:1.1.1k-12.el8_9 1:1.1.1k-16.el8_6 openssl: Use After Free with SSL_free_buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-4741

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-11-13 11:15 修改: 2026-04-15 00:35

openssl-libs CVE-2024-5535 高危 1:1.1.1k-12.el8_9 1:1.1.1k-14.el8_6 openssl: SSL_select_next_proto buffer overread

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-5535

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-06-27 11:15 修改: 2026-05-12 12:17

openssl-libs CVE-2026-45447 高危 1:1.1.1k-12.el8_9 1:1.1.1k-16.el8_6 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45447

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-06-09 17:17 修改: 2026-06-16 02:56

pam CVE-2024-10963 高危 1.3.1-34.0.1.el8_10 1.3.1-36.0.1.el8_10 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10963

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-11-07 16:15 修改: 2026-04-15 00:35

pam CVE-2025-6020 高危 1.3.1-34.0.1.el8_10 1.3.1-38.0.1.el8_10 linux-pam: Linux-pam directory Traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6020

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-17 13:15 修改: 2026-05-12 13:17

sqlite-libs CVE-2025-6965 高危 3.26.0-19.0.1.el8_9 3.26.0-20.el8_10 sqlite: Integer Truncation in SQLite

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6965

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-15 14:15 修改: 2026-04-14 10:16

glibc-minimal-langpack CVE-2026-0915 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-15 22:16 修改: 2026-01-23 19:36

glibc-minimal-langpack CVE-2026-4046 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.37 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

bzip2-libs CVE-2019-12900 中危 1.0.6-26.el8 1.0.6-28.el8_10 bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail).

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-12900

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2019-06-19 23:15 修改: 2025-06-09 16:15

curl CVE-2025-9086 中危 7.61.1-34.el8_10.2 7.61.1-34.el8_10.9 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-09-12 06:15 修改: 2026-06-02 14:16

expat CVE-2024-50602 中危 2.2.5-15.0.1.el8_10 2.2.5-16.0.1.el8_10 libexpat: expat: DoS via XML_ResumeParser

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-50602

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-10-27 05:15 修改: 2025-10-15 17:54

expat CVE-2024-8176 中危 2.2.5-15.0.1.el8_10 2.2.5-17.0.1.el8_10 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-8176

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-03-14 09:15 修改: 2026-04-15 00:35

glib2 CVE-2024-34397 中危 2.56.4-162.el8 2.56.4-166.el8_10 glib2: Signal subscription vulnerabilities

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34397

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-05-07 18:15 修改: 2026-05-12 12:16

glib2 CVE-2024-52533 中危 2.56.4-162.el8 2.56.4-166.el8_10 glib: buffer overflow in set_connect_msg()

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52533

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-11-11 23:15 修改: 2025-06-17 01:23

glib2 CVE-2025-13601 中危 2.56.4-162.el8 2.56.4-168.el8_10 glib: Integer overflow in in g_escape_uri_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13601

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-11-26 15:15 修改: 2026-06-02 14:16

glib2 CVE-2025-14087 中危 2.56.4-162.el8 2.56.4-169.el8_10 glib: GLib: Buffer underflow in GVariant parser leads to heap corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14087

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-10 09:15 修改: 2026-06-10 18:16

glib2 CVE-2025-14512 中危 2.56.4-162.el8 2.56.4-169.el8_10 glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14512

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-11 07:16 修改: 2026-06-10 18:16

glib2 CVE-2025-4373 中危 2.56.4-162.el8 2.56.4-166.el8_10 glib: Buffer Underflow on GLib through glib/gstring.c via function g_string_insert_unichar

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4373

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-06 15:16 修改: 2026-05-12 13:17

glibc CVE-2025-0395 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.16 glibc: buffer overflow in the GNU C Library's assert()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-22 13:15 修改: 2026-05-12 13:16

glibc CVE-2025-15281 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-20 14:16 修改: 2026-02-05 17:43

gnutls CVE-2024-12243 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.3 gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12243

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-02-10 16:15 修改: 2026-05-12 12:16

gnutls CVE-2025-14831 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.5 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14831

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-02-09 15:16 修改: 2026-06-10 18:16

gnutls CVE-2025-32988 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.4 gnutls: Vulnerability in GnuTLS otherName SAN export

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32988

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-10 08:15 修改: 2026-05-12 13:16

gnutls CVE-2025-32990 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.4 gnutls: Vulnerability in GnuTLS certtool template parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32990

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-10 10:15 修改: 2026-04-20 22:16

gnutls CVE-2025-6395 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.4 gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-10 16:15 修改: 2026-05-12 13:17

gnutls CVE-2025-9820 中危 3.6.16-8.el8_9.3 3.6.16-8.el8_10.5 gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9820

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-26 20:16 修改: 2026-05-12 13:17

glibc CVE-2025-4802 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.22 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4802

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-16 20:15 修改: 2025-11-03 20:19

glibc CVE-2025-8058 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.25 glibc: Double free in glibc

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8058

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-23 20:15 修改: 2026-04-15 00:35

glibc CVE-2026-0915 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-15 22:16 修改: 2026-01-23 19:36

krb5-libs CVE-2025-24528 中危 1.18.2-29.0.1.el8_10 1.18.2-31.0.1.el8_10 krb5: overflow when calculating ulog block size

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24528

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-16 18:16 修改: 2026-04-15 00:35

krb5-libs CVE-2025-3576 中危 1.18.2-29.0.1.el8_10 1.18.2-32.0.1.el8_10 krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-3576

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-04-15 06:15 修改: 2026-05-12 13:17

glibc CVE-2026-4046 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.37 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

glibc-common CVE-2025-0395 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.16 glibc: buffer overflow in the GNU C Library's assert()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-22 13:15 修改: 2026-05-12 13:16

glibc-common CVE-2025-15281 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-20 14:16 修改: 2026-02-05 17:43

libblkid CVE-2025-14104 中危 2.32.1-46.0.1.el8 2.32.1-48.0.1.el8_10 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14104

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-05 17:16 修改: 2026-04-19 20:16

glibc-common CVE-2025-4802 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.22 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4802

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-16 20:15 修改: 2025-11-03 20:19

libcurl CVE-2025-9086 中危 7.61.1-34.el8_10.2 7.61.1-34.el8_10.9 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-09-12 06:15 修改: 2026-06-02 14:16

libgcc CVE-2020-11023 中危 8.5.0-22.0.1.el8_10 8.5.0-23.0.1.el8_10 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-11023

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2020-04-29 21:15 修改: 2025-11-07 19:32

libmount CVE-2025-14104 中危 2.32.1-46.0.1.el8 2.32.1-48.0.1.el8_10 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14104

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-05 17:16 修改: 2026-04-19 20:16

glibc-common CVE-2025-8058 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.25 glibc: Double free in glibc

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8058

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-23 20:15 修改: 2026-04-15 00:35

libnsl CVE-2025-0395 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.16 glibc: buffer overflow in the GNU C Library's assert()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-22 13:15 修改: 2026-05-12 13:16

libnsl CVE-2025-15281 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-20 14:16 修改: 2026-02-05 17:43

libnsl CVE-2025-4802 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.22 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4802

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-16 20:15 修改: 2025-11-03 20:19

libnsl CVE-2025-8058 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.25 glibc: Double free in glibc

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8058

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-23 20:15 修改: 2026-04-15 00:35

libnsl CVE-2026-0915 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-15 22:16 修改: 2026-01-23 19:36

libnsl CVE-2026-4046 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.37 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

libquadmath CVE-2020-11023 中危 8.5.0-22.0.1.el8_10 8.5.0-23.0.1.el8_10 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-11023

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2020-04-29 21:15 修改: 2025-11-07 19:32

libsmartcols CVE-2025-14104 中危 2.32.1-46.0.1.el8 2.32.1-48.0.1.el8_10 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14104

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-05 17:16 修改: 2026-04-19 20:16

libssh CVE-2025-5318 中危 0.9.6-14.el8 0.9.6-15.el8_10 libssh: out-of-bounds read in sftp_handle()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5318

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-06-24 14:15 修改: 2026-02-27 17:16

libssh CVE-2025-5372 中危 0.9.6-14.el8 0.9.6-16.el8_10 libssh: Incorrect Return Code Handling in ssh_kdf() in libssh

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5372

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-04 06:15 修改: 2026-06-15 03:16

libstdc++ CVE-2020-11023 中危 8.5.0-22.0.1.el8_10 8.5.0-23.0.1.el8_10 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-11023

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2020-04-29 21:15 修改: 2025-11-07 19:32

libtasn1 CVE-2024-12133 中危 4.13-4.el8_7 4.13-5.el8_10 libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12133

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-02-10 16:15 修改: 2026-05-12 12:16

libuuid CVE-2025-14104 中危 2.32.1-46.0.1.el8 2.32.1-48.0.1.el8_10 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14104

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-12-05 17:16 修改: 2026-04-19 20:16

glibc-common CVE-2026-0915 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-15 22:16 修改: 2026-01-23 19:36

glibc-common CVE-2026-4046 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.37 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

glibc-gconv-extra CVE-2025-0395 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.16 glibc: buffer overflow in the GNU C Library's assert()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-22 13:15 修改: 2026-05-12 13:16

glibc-gconv-extra CVE-2025-15281 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-20 14:16 修改: 2026-02-05 17:43

glibc-gconv-extra CVE-2025-4802 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.22 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4802

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-16 20:15 修改: 2025-11-03 20:19

glibc-gconv-extra CVE-2025-8058 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.25 glibc: Double free in glibc

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8058

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-23 20:15 修改: 2026-04-15 00:35

libxml2 CVE-2022-49043 中危 2.9.7-18.el8_10.1 2.9.7-18.el8_10.2 libxml: use-after-free in xmlXIncludeAddNode

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-49043

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-26 06:15 修改: 2025-11-03 21:15

libxml2 CVE-2025-32414 中危 2.9.7-18.el8_10.1 2.9.7-20.el8_10 libxml2: Out-of-Bounds Read in libxml2

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32414

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-04-08 03:15 修改: 2025-11-03 20:18

libxml2 CVE-2025-32415 中危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.3 libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32415

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-04-17 17:15 修改: 2025-11-03 20:18

libxml2 CVE-2025-9714 中危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.4 libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9714

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-09-10 19:15 修改: 2026-05-12 13:17

lz4-libs CVE-2019-17543 中危 1.8.3-3.el8_4 1.8.3-5.el8_10 lz4: heap-based buffer overflow in LZ4_write32

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-17543

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2019-10-14 02:15 修改: 2024-11-21 04:32

glibc-gconv-extra CVE-2026-0915 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: glibc: Information disclosure via zero-valued network query

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0915

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-15 22:16 修改: 2026-01-23 19:36

glibc-gconv-extra CVE-2026-4046 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.37 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

glibc-minimal-langpack CVE-2025-0395 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.16 glibc: buffer overflow in the GNU C Library's assert()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0395

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-01-22 13:15 修改: 2026-05-12 13:16

openssl-libs CVE-2025-69419 中危 1:1.1.1k-12.el8_9 1:1.1.1k-15.el8_6 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-27 16:16 修改: 2026-05-12 13:17

openssl-libs CVE-2025-9230 中危 1:1.1.1k-12.el8_9 1:1.1.1k-14.el8_10 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9230

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-09-30 14:15 修改: 2026-06-02 14:16

glibc-minimal-langpack CVE-2025-15281 中危 2.28-251.0.2.el8_10.5 2.28-251.0.4.el8_10.31 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15281

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2026-01-20 14:16 修改: 2026-02-05 17:43

glibc-minimal-langpack CVE-2025-4802 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.22 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4802

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-16 20:15 修改: 2025-11-03 20:19

pam CVE-2024-10041 中危 1.3.1-34.0.1.el8_10 1.3.1-36.0.1.el8_10 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

glibc-minimal-langpack CVE-2025-8058 中危 2.28-251.0.2.el8_10.5 2.28-251.0.3.el8_10.25 glibc: Double free in glibc

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8058

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-07-23 20:15 修改: 2026-04-15 00:35

systemd-libs CVE-2025-4598 中危 239-82.0.2.el8 239-82.0.4.el8_10.5 systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4598

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2025-05-30 14:15 修改: 2026-05-19 16:16

libxml2 CVE-2024-34459 低危 2.9.7-18.el8_10.1 2.9.7-21.el8_10.5 libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34459

镜像层: sha256:96dd4ec9858121674742f91b806af3773c6e210cde93a9e98f86956561b4e3e9

发布日期: 2024-05-14 15:39 修改: 2025-11-04 22:16

Java (jar)
低危漏洞:1 中危漏洞:23 高危漏洞:20 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
org.quartz-scheduler:quartz CVE-2019-13990 严重 2.2.2 2.3.2 libquartz: XXE attacks via job description

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-13990

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2019-07-26 19:15 修改: 2024-11-21 04:25

com.google.code.gson:gson CVE-2022-25647 高危 1.4 2.8.9 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-25647

镜像层: sha256:5439be54b48ed88bdde287c7ac37c6780102dd9304a382dace1714bd0cfed780

发布日期: 2022-05-01 16:15 修改: 2024-11-21 06:52

com.google.protobuf:protobuf-java CVE-2021-22569 高危 3.5.1 3.16.1, 3.18.2, 3.19.2 protobuf-java: potential DoS in the parsing procedure for binary data

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-22569

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-01-10 14:10 修改: 2024-11-21 05:50

com.google.protobuf:protobuf-java CVE-2022-3509 高危 3.5.1 3.16.3, 3.19.6, 3.20.3, 3.21.7 protobuf-java: Textformat parsing issue leads to DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3509

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-12-12 13:15 修改: 2025-04-22 15:15

com.google.protobuf:protobuf-java CVE-2022-3510 高危 3.5.1 3.16.3, 3.19.6, 3.20.3, 3.21.7 protobuf-java: Message-Type Extensions parsing issue leads to DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3510

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-12-12 13:15 修改: 2025-04-22 15:15

com.google.protobuf:protobuf-java CVE-2024-7254 高危 3.5.1 3.25.5, 4.27.5, 4.28.2 protobuf: StackOverflow vulnerability in Protocol Buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2024-09-19 01:15 修改: 2025-09-26 17:10

commons-fileupload:commons-fileupload CVE-2023-24998 高危 1.3.3 1.5 FileUpload: FileUpload DoS with excessive parts

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-24998

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-02-20 16:15 修改: 2025-11-03 22:16

commons-fileupload:commons-fileupload CVE-2025-48976 高危 1.3.3 1.6.0 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48976

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2025-06-16 15:15 修改: 2025-11-03 20:19

commons-io:commons-io CVE-2024-47554 高危 2.6 2.14.0 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47554

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2024-10-03 12:15 修改: 2025-07-10 21:10

org.apache.xmlgraphics:xmlgraphics-commons CVE-2020-11988 高危 2.2 2.6 xmlgraphics-commons: SSRF due to improper input validation by the XMPParser

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-11988

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2021-02-24 18:15 修改: 2024-11-21 04:59

org.owasp.esapi:esapi CVE-2022-23457 高危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23457

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-25 20:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-23457 高危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23457

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-25 20:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-23457 高危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23457

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-25 20:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-23457 高危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23457

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-25 20:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-23457 高危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23457

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-25 20:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi GHSA-7c2q-5qmr-v76q 高危 2.1.0.1 2.5.2.0 DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998

漏洞详情: https://github.com/advisories/GHSA-7c2q-5qmr-v76q

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-27 21:55 修改: 2023-10-27 21:55

org.owasp.esapi:esapi GHSA-7c2q-5qmr-v76q 高危 2.1.0.1 2.5.2.0 DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998

漏洞详情: https://github.com/advisories/GHSA-7c2q-5qmr-v76q

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-27 21:55 修改: 2023-10-27 21:55

org.owasp.esapi:esapi GHSA-7c2q-5qmr-v76q 高危 2.1.0.1 2.5.2.0 DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998

漏洞详情: https://github.com/advisories/GHSA-7c2q-5qmr-v76q

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-27 21:55 修改: 2023-10-27 21:55

org.owasp.esapi:esapi GHSA-7c2q-5qmr-v76q 高危 2.1.0.1 2.5.2.0 DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998

漏洞详情: https://github.com/advisories/GHSA-7c2q-5qmr-v76q

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-27 21:55 修改: 2023-10-27 21:55

org.owasp.esapi:esapi GHSA-7c2q-5qmr-v76q 高危 2.1.0.1 2.5.2.0 DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998

漏洞详情: https://github.com/advisories/GHSA-7c2q-5qmr-v76q

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-27 21:55 修改: 2023-10-27 21:55

com.fasterxml.jackson.core:jackson-core CVE-2025-52999 高危 2.9.3 2.15.0 com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52999

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2025-06-25 17:15 修改: 2026-04-15 00:35

org.owasp.antisamy:antisamy CVE-2023-43643 中危 1.5.7 1.7.4 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-43643

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-10-09 14:15 修改: 2024-11-21 08:24

org.owasp.antisamy:antisamy CVE-2024-23635 中危 1.5.7 1.7.5 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23635

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2024-02-02 17:15 修改: 2024-11-21 08:58

com.google.protobuf:protobuf-java CVE-2022-3171 中危 3.5.1 3.21.7, 3.20.3, 3.19.6, 3.16.3 protobuf-java: timeout in parser leads to DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3171

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-10-12 23:15 修改: 2024-11-21 07:18

com.jcraft:jsch CVE-2016-5725 中危 0.1.44 0.1.54 jsch: ChannelSftp path traversal vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-5725

镜像层: sha256:5439be54b48ed88bdde287c7ac37c6780102dd9304a382dace1714bd0cfed780

发布日期: 2017-01-19 22:59 修改: 2026-05-13 00:24

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.9.3 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

com.fasterxml.jackson.core:jackson-core CVE-2025-49128 中危 2.9.3 2.13.0 com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49128

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2025-06-06 22:15 修改: 2026-04-15 00:35

com.google.guava:guava CVE-2018-10237 中危 23.1-jre 24.1.1-android guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-10237

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2018-04-26 21:29 修改: 2024-11-21 03:41

commons-io:commons-io CVE-2021-29425 中危 2.6 2.7 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-29425

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2021-04-13 07:15 修改: 2024-11-21 06:01

org.apache.httpcomponents:httpclient CVE-2020-13956 中危 4.5.5 4.5.13, 5.0.3 apache-httpclient: incorrect handling of malformed authority component in request URIs

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-13956

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2020-12-02 17:15 修改: 2025-12-01 16:15

com.google.guava:guava CVE-2023-2976 中危 23.1-jre 32.0.0-android guava: insecure temporary directory creation

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-2976

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-06-14 18:15 修改: 2026-02-25 18:16

org.owasp.antisamy:antisamy CVE-2021-35043 中危 1.5.7 1.6.4 AntiSamy: XSS via HTML attributes

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-35043

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2021-07-19 15:15 修改: 2024-11-21 06:11

org.owasp.antisamy:antisamy CVE-2022-28367 中危 1.5.7 1.6.6 OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-28367

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-21 23:15 修改: 2024-11-21 06:57

org.owasp.esapi:esapi CVE-2022-24891 中危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24891

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-27 21:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-24891 中危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24891

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-27 21:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-24891 中危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24891

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-27 21:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-24891 中危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24891

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-27 21:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi CVE-2022-24891 中危 2.1.0.1 2.3.0.0 ESAPI (The OWASP Enterprise Security API) is a free, open source, web ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24891

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-27 21:15 修改: 2025-11-03 20:15

org.owasp.esapi:esapi GHSA-r68h-jhhj-9jvm 中危 2.1.0.1 2.6.0.0 Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year

漏洞详情: https://github.com/advisories/GHSA-r68h-jhhj-9jvm

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-11-27 17:25 修改: 2024-11-26 18:53

org.owasp.esapi:esapi GHSA-r68h-jhhj-9jvm 中危 2.1.0.1 2.6.0.0 Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year

漏洞详情: https://github.com/advisories/GHSA-r68h-jhhj-9jvm

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-11-27 17:25 修改: 2024-11-26 18:53

org.owasp.esapi:esapi GHSA-r68h-jhhj-9jvm 中危 2.1.0.1 2.6.0.0 Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year

漏洞详情: https://github.com/advisories/GHSA-r68h-jhhj-9jvm

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-11-27 17:25 修改: 2024-11-26 18:53

org.owasp.esapi:esapi GHSA-r68h-jhhj-9jvm 中危 2.1.0.1 2.6.0.0 Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year

漏洞详情: https://github.com/advisories/GHSA-r68h-jhhj-9jvm

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-11-27 17:25 修改: 2024-11-26 18:53

org.owasp.esapi:esapi GHSA-r68h-jhhj-9jvm 中危 2.1.0.1 2.6.0.0 Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year

漏洞详情: https://github.com/advisories/GHSA-r68h-jhhj-9jvm

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2023-11-27 17:25 修改: 2024-11-26 18:53

org.owasp.antisamy:antisamy CVE-2022-29577 中危 1.5.7 1.6.7 Cross-site Scripting in OWASP AntiSamy

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-29577

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2022-04-21 23:15 修改: 2024-11-21 06:59

com.google.guava:guava CVE-2020-8908 低危 23.1-jre 32.0.0-android guava: local information disclosure via temporary directory created with unsafe permissions

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-8908

镜像层: sha256:e9575428603cbf1de140ae30e6fe810c8e7adfb0bedafa43490677d329ec46d3

发布日期: 2020-12-10 23:15 修改: 2026-02-23 21:17

检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×