docker.io/onlyoffice/controlpanel:latest linux/amd64

docker.io/onlyoffice/controlpanel:latest - Trivy安全扫描结果 扫描时间: 2025-01-24 15:49
全部漏洞信息
低危漏洞:78 中危漏洞:42 高危漏洞:6 严重漏洞:0

系统OS: ubuntu 22.04 扫描引擎: Trivy 扫描时间: 2025-01-24 15:49

docker.io/onlyoffice/controlpanel:latest (ubuntu 22.04) (ubuntu)
低危漏洞:72 中危漏洞:35 高危漏洞:1 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
docker.io CVE-2024-41110 高危 24.0.7-0ubuntu2~22.04.1 moby: Authz zero length regression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41110

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-07-24 17:15 修改: 2024-07-30 20:15

docker.io CVE-2023-28840 中危 24.0.7-0ubuntu2~22.04.1 moby: Encrypted overlay network may be unauthenticated

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28840

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-04-04 22:15 修改: 2023-09-15 21:15

docker.io CVE-2023-28841 中危 24.0.7-0ubuntu2~22.04.1 moby: Encrypted overlay network traffic may be unencrypted

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28841

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-04-04 22:15 修改: 2023-09-15 21:15

docker.io CVE-2023-28842 中危 24.0.7-0ubuntu2~22.04.1 moby: Encrypted overlay network with a single endpoint is unauthenticated

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28842

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-04-04 22:15 修改: 2023-09-15 21:15

docker.io CVE-2024-23650 中危 24.0.7-0ubuntu2~22.04.1 moby/buildkit: Possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23650

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:38

docker.io CVE-2024-23651 中危 24.0.7-0ubuntu2~22.04.1 moby/buildkit: possible race condition with accessing subpaths from cache mounts

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23651

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:43

docker.io CVE-2024-23652 中危 24.0.7-0ubuntu2~22.04.1 moby/buildkit: possible host system access from mount stub cleaner

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23652

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

docker.io CVE-2024-23653 中危 24.0.7-0ubuntu2~22.04.1 moby/buildkit: Buildkit's interactive containers API does not validate entitlements check

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23653

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-31 22:15 修改: 2024-02-09 01:44

docker.io CVE-2024-24557 中危 24.0.7-0ubuntu2~22.04.1 moby: classic builder cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24557

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-02-01 17:15 修改: 2024-02-09 20:21

docker.io CVE-2024-29018 中危 24.0.7-0ubuntu2~22.04.1 moby: external DNS requests from 'internal' networks could lead to data exfiltration

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29018

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-03-20 21:15 修改: 2024-03-21 12:58

docker.io CVE-2024-32473 中危 24.0.7-0ubuntu2~22.04.1 moby: IPv6 enabled on IPv4-only network interfaces

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-32473

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-04-18 22:15 修改: 2024-04-19 13:10

gcc-12-base CVE-2023-4039 中危 12.3.0-1ubuntu1~22.04 gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-4039

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-09-13 09:15 修改: 2024-08-02 08:15

git CVE-2024-50349 中危 1:2.34.1-1ubuntu1.11 1:2.34.1-1ubuntu1.12 git: Git does not sanitize URLs when asking for credentials interactively

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-50349

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

git CVE-2024-52006 中危 1:2.34.1-1ubuntu1.11 1:2.34.1-1ubuntu1.12 git: Newline confusion in credential helpers can lead to credential exfiltration in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52006

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

git-man CVE-2024-50349 中危 1:2.34.1-1ubuntu1.11 1:2.34.1-1ubuntu1.12 git: Git does not sanitize URLs when asking for credentials interactively

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-50349

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

git-man CVE-2024-52006 中危 1:2.34.1-1ubuntu1.11 1:2.34.1-1ubuntu1.12 git: Newline confusion in credential helpers can lead to credential exfiltration in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52006

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2025-01-14 19:15 修改: 2025-01-14 19:15

libgcc-s1 CVE-2023-4039 中危 12.3.0-1ubuntu1~22.04 gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-4039

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-09-13 09:15 修改: 2024-08-02 08:15

libgssapi-krb5-2 CVE-2024-26462 中危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libk5crypto3 CVE-2024-26462 中危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libkrb5-3 CVE-2024-26462 中危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libkrb5support0 CVE-2024-26462 中危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libpam-modules CVE-2024-10041 中危 1.4.0-11ubuntu2.4 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam-modules-bin CVE-2024-10041 中危 1.4.0-11ubuntu2.4 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam-runtime CVE-2024-10041 中危 1.4.0-11ubuntu2.4 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam0g CVE-2024-10041 中危 1.4.0-11ubuntu2.4 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpython3.10-minimal CVE-2024-11168 中危 3.10.12-1~22.04.7 python: Improper validation of IPv6 and IPvFuture addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11168

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-11-12 22:15 修改: 2025-01-06 18:15

libpython3.10-stdlib CVE-2024-11168 中危 3.10.12-1~22.04.7 python: Improper validation of IPv6 and IPvFuture addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11168

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-11-12 22:15 修改: 2025-01-06 18:15

libstdc++6 CVE-2023-4039 中危 12.3.0-1ubuntu1~22.04 gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-4039

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-09-13 09:15 修改: 2024-08-02 08:15

login CVE-2024-56433 中危 1:4.8.1-2ubuntu2.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

nodejs CVE-2022-40735 中危 16.20.2-1nodesource1

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40735

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2022-11-14 23:15 修改: 2024-04-23 07:15

nodejs CVE-2023-5363 中危 16.20.2-1nodesource1 openssl: Incorrect cipher key and IV length processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5363

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-10-25 18:17 修改: 2024-10-14 15:15

nodejs CVE-2024-6119 中危 16.20.2-1nodesource1 openssl: Possible denial of service in X.509 name checks

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6119

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-09-03 16:15 修改: 2024-09-03 21:35

passwd CVE-2024-56433 中危 1:4.8.1-2ubuntu2.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

python3.10 CVE-2024-11168 中危 3.10.12-1~22.04.7 python: Improper validation of IPv6 and IPvFuture addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11168

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-11-12 22:15 修改: 2025-01-06 18:15

python3.10-minimal CVE-2024-11168 中危 3.10.12-1~22.04.7 python: Improper validation of IPv6 and IPvFuture addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-11168

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-11-12 22:15 修改: 2025-01-06 18:15

wget CVE-2021-31879 中危 1.21.2-2ubuntu1.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2021-04-29 05:15 修改: 2022-05-13 20:52

coreutils CVE-2016-2781 低危 8.32-4.1ubuntu1.2 coreutils: Non-privileged session can escape to the parent session in chroot

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2781

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2017-02-07 15:59 修改: 2023-11-07 02:32

libgcc-s1 CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2022-03-26 13:15 修改: 2023-11-07 03:45

libgcrypt20 CVE-2024-2236 低危 1.9.4-3ubuntu3 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-03-06 22:15 修改: 2024-11-12 18:15

dbus CVE-2023-34969 低危 1.12.20-2ubuntu4.1 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-34969

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-06-08 03:15 修改: 2023-12-27 16:36

libgssapi-krb5-2 CVE-2024-26458 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libgssapi-krb5-2 CVE-2024-26461 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

git CVE-2018-1000021 低危 1:2.34.1-1ubuntu1.11 git: client prints server-sent ANSI escape codes to the terminal, allowing for unverified messages to potentially execute arbitrary commands

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-1000021

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2018-02-09 23:29 修改: 2024-10-24 17:58

libk5crypto3 CVE-2024-26458 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libk5crypto3 CVE-2024-26461 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

dirmngr CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libkrb5-3 CVE-2024-26458 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libkrb5-3 CVE-2024-26461 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

gcc-12-base CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2022-03-26 13:15 修改: 2023-11-07 03:45

libkrb5support0 CVE-2024-26458 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libkrb5support0 CVE-2024-26461 低危 1.19.2-2ubuntu0.4 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

libncurses6 CVE-2023-45918 低危 6.3-2ubuntu0.1 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45918

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-16 22:15 修改: 2024-11-21 21:15

libncurses6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-12 15:15 修改: 2024-01-31 03:15

libncursesw6 CVE-2023-45918 低危 6.3-2ubuntu0.1 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45918

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-16 22:15 修改: 2024-11-21 21:15

libncursesw6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-12 15:15 修改: 2024-01-31 03:15

git-man CVE-2018-1000021 低危 1:2.34.1-1ubuntu1.11 git: client prints server-sent ANSI escape codes to the terminal, allowing for unverified messages to potentially execute arbitrary commands

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-1000021

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2018-02-09 23:29 修改: 2024-10-24 17:58

gnupg CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gnupg-l10n CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gnupg-utils CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libpcre2-8-0 CVE-2022-41409 低危 10.39-3ubuntu0.1 pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-41409

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-07-18 14:15 修改: 2023-07-27 03:46

libpcre3 CVE-2017-11164 低危 2:8.39-13ubuntu0.22.04.1 pcre: OP_KETRMAX feature in the match function in pcre_exec.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-11164

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2017-07-11 03:29 修改: 2023-11-07 02:38

gnupg2 CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpg CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libssl3 CVE-2024-41996 低危 3.0.2-0ubuntu1.18 openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41996

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-08-26 06:15 修改: 2024-08-26 16:35

gpg-agent CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libstdc++6 CVE-2022-27943 低危 12.3.0-1ubuntu1~22.04 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-27943

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2022-03-26 13:15 修改: 2023-11-07 03:45

libsystemd0 CVE-2023-7008 低危 249.11-0ubuntu3.12 systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-7008

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-23 13:15 修改: 2024-11-22 12:15

libtinfo6 CVE-2023-45918 低危 6.3-2ubuntu0.1 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45918

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-16 22:15 修改: 2024-11-21 21:15

libtinfo6 CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-12 15:15 修改: 2024-01-31 03:15

libudev1 CVE-2023-7008 低危 249.11-0ubuntu3.12 systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-7008

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-23 13:15 修改: 2024-11-22 12:15

libzstd1 CVE-2022-4899 低危 1.4.8+dfsg-3build1 zstd: mysql: buffer overrun in util.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-4899

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-03-31 20:15 修改: 2023-11-07 03:59

locales CVE-2016-20013 低危 2.35-0ubuntu3.8

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

gpg-wks-client CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

login CVE-2023-29383 低危 1:4.8.1-2ubuntu2.2 shadow: Improper input validation in shadow-utils package utility chfn

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-29383

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-04-14 22:15 修改: 2023-04-24 18:05

ncurses-base CVE-2023-45918 低危 6.3-2ubuntu0.1 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45918

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-16 22:15 修改: 2024-11-21 21:15

ncurses-base CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-12 15:15 修改: 2024-01-31 03:15

ncurses-bin CVE-2023-45918 低危 6.3-2ubuntu0.1 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45918

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2024-02-16 22:15 修改: 2024-11-21 21:15

ncurses-bin CVE-2023-50495 低危 6.3-2ubuntu0.1 ncurses: segmentation fault via _nc_wrap_entry()

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50495

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-12-12 15:15 修改: 2024-01-31 03:15

gpg-wks-server CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpgconf CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpgsm CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

nodejs CVE-2019-1563 低危 16.20.2-1nodesource1 openssl: information disclosure in PKCS7_dataDecode and CMS_decrypt_set1_pkey

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-1563

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2019-09-10 17:15 修改: 2023-11-07 03:08

nodejs CVE-2021-23840 低危 16.20.2-1nodesource1 openssl: integer overflow in CipherUpdate

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-23840

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2021-02-16 17:15 修改: 2024-06-21 19:15

nodejs CVE-2023-0464 低危 16.20.2-1nodesource1 openssl: Denial of service by excessive resource usage in verifying X509 policy constraints

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-0464

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-03-22 17:15 修改: 2024-06-21 19:15

nodejs CVE-2023-0465 低危 16.20.2-1nodesource1 openssl: Invalid certificate policies in leaf certificates are silently ignored

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-0465

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-03-28 15:15 修改: 2024-02-04 09:15

nodejs CVE-2023-0466 低危 16.20.2-1nodesource1 openssl: Certificate policy check not enabled

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-0466

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-03-28 15:15 修改: 2024-02-04 09:15

nodejs CVE-2023-1255 低危 16.20.2-1nodesource1 openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-1255

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-04-20 17:15 修改: 2023-09-08 17:15

nodejs CVE-2023-2975 低危 16.20.2-1nodesource1 openssl: AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-2975

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-07-14 12:15 修改: 2024-10-14 15:15

nodejs CVE-2023-3446 低危 16.20.2-1nodesource1 openssl: Excessive time spent checking DH keys and parameters

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-3446

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-07-19 12:15 修改: 2024-10-14 15:15

nodejs CVE-2023-3817 低危 16.20.2-1nodesource1 OpenSSL: Excessive time spent checking DH q parameter value

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-3817

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-07-31 16:15 修改: 2024-10-14 15:15

nodejs CVE-2023-5678 低危 16.20.2-1nodesource1 openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5678

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-11-06 16:15 修改: 2024-10-14 15:15

nodejs CVE-2023-6129 低危 16.20.2-1nodesource1 openssl: POLY1305 MAC implementation corrupts vector registers on PowerPC

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-6129

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-09 17:15 修改: 2024-10-14 15:15

nodejs CVE-2023-6237 低危 16.20.2-1nodesource1 openssl: Excessive time spent checking invalid RSA public keys

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-6237

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-04-25 07:15 修改: 2024-11-01 15:35

nodejs CVE-2024-0727 低危 16.20.2-1nodesource1 openssl: denial of service via null dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0727

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-01-26 09:15 修改: 2024-10-14 15:15

nodejs CVE-2024-2511 低危 16.20.2-1nodesource1 openssl: Unbounded memory growth with session handling in TLSv1.3

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2511

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-04-08 14:15 修改: 2024-10-14 15:15

nodejs CVE-2024-4603 低危 16.20.2-1nodesource1 openssl: Excessive time spent checking DSA keys and parameters

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-4603

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-05-16 16:15 修改: 2024-10-14 15:15

nodejs CVE-2024-4741 低危 16.20.2-1nodesource1 openssl: Use After Free with SSL_free_buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-4741

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-11-13 11:15 修改: 2024-11-13 17:01

nodejs CVE-2024-5535 低危 16.20.2-1nodesource1 openssl: SSL_select_next_proto buffer overread

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-5535

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-06-27 11:15 修改: 2024-07-12 14:15

nodejs CVE-2024-9143 低危 16.20.2-1nodesource1 openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-9143

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-10-16 17:15 修改: 2024-11-08 16:35

openssl CVE-2024-41996 低危 3.0.2-0ubuntu1.18 openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41996

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-08-26 06:15 修改: 2024-08-26 16:35

gpgv CVE-2022-3219 低危 2.2.27-3ubuntu2.1 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

passwd CVE-2023-29383 低危 1:4.8.1-2ubuntu2.2 shadow: Improper input validation in shadow-utils package utility chfn

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-29383

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2023-04-14 22:15 修改: 2023-04-24 18:05

patch CVE-2018-6952 低危 2.7.6-7build2 patch: Double free of memory in pch.c:another_hunk() causes a crash

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-6952

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2018-02-13 19:29 修改: 2019-04-17 20:29

patch CVE-2021-45261 低危 2.7.6-7build2 patch: Invalid Pointer via another_hunk function

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-45261

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2021-12-22 18:15 修改: 2021-12-28 14:24

libc-bin CVE-2016-20013 低危 2.35-0ubuntu3.8

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

libc6 CVE-2016-20013 低危 2.35-0ubuntu3.8

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:2573e0d8158209ed54ab25c87bcdcb00bd3d2539246960a3d592a1c599d70465

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

runc CVE-2024-45310 低危 1.1.12-0ubuntu2~22.04.1 runc: runc can be tricked into creating empty files/directories on host

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45310

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2024-09-03 19:15 修改: 2024-09-03 19:40

libdbus-1-3 CVE-2023-34969 低危 1.12.20-2ubuntu4.1 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-34969

镜像层: sha256:6b704839d339e88dc70fc21affa7cd4a8e36b6aec397c1cef0703f4f8a070272

发布日期: 2023-06-08 03:15 修改: 2023-12-27 16:36

Node.js (node-pkg)
低危漏洞:6 中危漏洞:7 高危漏洞:5 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
body-parser CVE-2024-45590 高危 1.20.1 1.20.3 body-parser: Denial of Service Vulnerability in body-parser

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45590

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-09-10 16:15 修改: 2024-09-20 16:26

http-cache-semantics CVE-2022-25881 高危 4.1.0 4.1.1 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-25881

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2023-01-31 05:15 修改: 2023-11-07 03:44

path-to-regexp CVE-2024-45296 高危 0.1.7 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0 path-to-regexp: Backtracking regular expressions cause ReDoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45296

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-09-09 19:15 修改: 2024-09-10 12:09

semver CVE-2022-25883 高危 5.7.1 7.5.2, 6.3.1, 5.7.2 nodejs-semver: Regular expression denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-25883

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2023-06-21 05:15 修改: 2024-12-06 17:15

semver CVE-2022-25883 高危 7.3.8 7.5.2, 6.3.1, 5.7.2 nodejs-semver: Regular expression denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-25883

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2023-06-21 05:15 修改: 2024-12-06 17:15

path-to-regexp CVE-2024-52798 中危 0.1.7 0.1.12 path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52798

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-12-05 23:15 修改: 2024-12-05 23:15

pug CVE-2024-36361 中危 3.0.2 3.0.3 Pug allows JavaScript code execution if an application accepts untrusted input

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-36361

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-05-24 06:15 修改: 2024-08-02 04:17

pug-code-gen CVE-2024-36361 中危 3.0.2 3.0.3 Pug allows JavaScript code execution if an application accepts untrusted input

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-36361

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-05-24 06:15 修改: 2024-08-02 04:17

request CVE-2023-28155 中危 2.88.2 The Request package through 2.88.1 for Node.js allows a bypass of SSRF ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28155

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2023-03-16 15:15 修改: 2024-08-02 13:15

express CVE-2024-29041 中危 4.18.2 4.19.2, 5.0.0-beta.3 express: cause malformed URLs to be evaluated

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29041

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-03-25 21:15 修改: 2024-03-26 12:55

got CVE-2022-33987 中危 9.6.0 12.1.0, 11.8.5 nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-33987

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2022-06-18 21:15 修改: 2022-06-28 16:15

tough-cookie CVE-2023-26136 中危 2.5.0 4.1.3 tough-cookie: prototype pollution in cookie memstore

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-26136

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2023-07-01 05:15 修改: 2024-06-21 19:15

cookie CVE-2024-47764 低危 0.4.1 0.7.0 cookie: cookie accepts cookie name, path, and domain with out of bounds characters

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47764

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-10-04 20:15 修改: 2024-10-07 17:48

express CVE-2024-43796 低危 4.18.2 4.20.0, 5.0.0 express: Improper Input Handling in Express Redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-43796

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-09-10 15:15 修改: 2024-09-20 16:07

cookie CVE-2024-47764 低危 0.4.2 0.7.0 cookie: cookie accepts cookie name, path, and domain with out of bounds characters

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47764

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-10-04 20:15 修改: 2024-10-07 17:48

send CVE-2024-43799 低危 0.18.0 0.19.0 send: Code Execution Vulnerability in Send Library

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-43799

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-09-10 15:15 修改: 2024-09-20 16:57

serve-static CVE-2024-43800 低危 1.15.0 1.16.0, 2.1.0 serve-static: Improper Sanitization in serve-static

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-43800

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-09-10 15:15 修改: 2024-09-20 17:36

cookie CVE-2024-47764 低危 0.5.0 0.7.0 cookie: cookie accepts cookie name, path, and domain with out of bounds characters

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47764

镜像层: sha256:6b2eae53743a1ca2570ca0921e5ffb16bda93b0dc470c83aa9b989739c1fb07a

发布日期: 2024-10-04 20:15 修改: 2024-10-07 17:48