gcr.io/distroless/java-base-debian13:latest linux/amd64

gcr.io/distroless/java-base-debian13:latest - Trivy安全扫描结果 扫描时间: 2026-06-26 17:20
全部漏洞信息
低危漏洞:14 中危漏洞:21 高危漏洞:3 严重漏洞:0

系统OS: debian 13.5 扫描引擎: Trivy 扫描时间: 2026-06-26 17:20

gcr.io/distroless/java-base-debian13:latest (debian 13.5) (debian)
低危漏洞:14 中危漏洞:21 高危漏洞:3 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
libexpat1 CVE-2025-59375 高危 2.7.1-2 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59375

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2025-09-15 03:15 修改: 2026-06-17 09:46

libexpat1 CVE-2026-25210 高危 2.7.1-2 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25210

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-01-30 07:16 修改: 2026-06-17 10:24

libexpat1 CVE-2026-45186 高危 2.7.1-2 libexpat: denial of service via crafted XML input

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45186

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-05-10 07:16 修改: 2026-06-17 10:51

libc6 CVE-2026-5928 中危 2.41-12+deb13u3 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5928

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2026-04-20 21:16 修改: 2026-06-17 10:59

libc6 CVE-2026-6238 中危 2.41-12+deb13u3 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2026-04-28 19:37 修改: 2026-06-19 21:17

libbz2-1.0 CVE-2026-42250 中危 1.0.8-6 bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42250

镜像层: sha256:953871f68b73a0c29f9268de527a33d56fb21e904f9b3b9a52281ead677a015a

发布日期: 2026-05-28 14:16 修改: 2026-06-17 10:47

libc6 CVE-2026-5435 中危 2.41-12+deb13u3 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2026-04-28 13:19 修改: 2026-06-17 10:59

libc6 CVE-2026-5450 中危 2.41-12+deb13u3 glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5450

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2026-04-20 21:16 修改: 2026-06-17 10:59

libexpat1 CVE-2025-66382 中危 2.7.1-2 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2025-11-28 07:15 修改: 2026-06-17 09:56

libexpat1 CVE-2026-32776 中危 2.7.1-2 libexpat: libexpat: Denial of Service due to NULL pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32776

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

libexpat1 CVE-2026-32777 中危 2.7.1-2 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32777

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

libexpat1 CVE-2026-32778 中危 2.7.1-2 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32778

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

libexpat1 CVE-2026-50219 中危 2.7.1-2 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50219

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-04 06:16 修改: 2026-06-17 10:57

libexpat1 CVE-2026-56132 中危 2.7.1-2 In libexpat before 2.8.2, there is a heap-based buffer overflow in doP ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56132

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-19 06:17 修改: 2026-06-23 20:15

libexpat1 CVE-2026-56403 中危 2.7.1-2 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56403

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 20:15

libexpat1 CVE-2026-56404 中危 2.7.1-2 libexpat before 2.8.2 has an integer overflow in addBinding.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56404

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 20:15

libexpat1 CVE-2026-56405 中危 2.7.1-2 libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56405

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 20:14

libexpat1 CVE-2026-56406 中危 2.7.1-2 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56406

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 16:29

libexpat1 CVE-2026-56410 中危 2.7.1-2 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56410

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 16:18

libexpat1 CVE-2026-56411 中危 2.7.1-2 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56411

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 17:16 修改: 2026-06-23 16:16

libexpat1 CVE-2026-56412 中危 2.7.1-2 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56412

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 17:16 修改: 2026-06-23 15:31

libuuid1 CVE-2026-27456 中危 2.41-5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 2026-04-03 22:16 修改: 2026-06-17 10:27

libuuid1 CVE-2026-3184 中危 2.41-5 util-linux: util-linux: Access control bypass due to improper hostname canonicalization

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3184

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 2026-04-03 19:17 修改: 2026-06-17 10:43

zlib1g CVE-2026-27171 中危 1:1.3.dfsg+really1.3.1-1+b1 zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27171

镜像层: sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0

发布日期: 2026-02-18 04:16 修改: 2026-06-17 10:26

libc6 CVE-2019-1010025 低危 2.41-12+deb13u3 glibc: information disclosure of heap addresses of pthread_created thread

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-1010025

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-07-15 04:15 修改: 2026-06-17 02:09

libc6 CVE-2019-9192 低危 2.41-12+deb13u3 glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-9192

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-02-26 18:29 修改: 2026-06-17 02:43

libc6 CVE-2010-4756 低危 2.41-12+deb13u3 glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions

漏洞详情: https://avd.aquasec.com/nvd/cve-2010-4756

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2011-03-02 20:00 修改: 2026-04-29 01:13

libc6 CVE-2018-20796 低危 2.41-12+deb13u3 glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-20796

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-02-26 02:29 修改: 2026-06-17 01:53

libexpat1 CVE-2026-24515 低危 2.7.1-2 libexpat: libexpat null pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24515

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-01-23 08:16 修改: 2026-06-17 10:23

libexpat1 CVE-2026-41080 低危 2.7.1-2 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41080

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-04-16 17:16 修改: 2026-06-17 10:46

liblcms2-2 CVE-2025-29070 低危 2.16-2+deb13u2 A heap buffer overflow vulnerability has been identified in thesmooth2 ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-29070

镜像层: sha256:29d492a034557b4b338ab6ef33e3f1ecfaaa340ff721aae0776149b59cc7052d

发布日期: 2025-04-01 21:15 修改: 2026-06-17 09:05

libpng16-16t64 CVE-2021-4214 低危 1.6.48-1+deb13u5 libpng: hardcoded value leads to heap-overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-4214

镜像层: sha256:b25b5b4e7b93b4c0b8b9a8fe94063231389989d767c227027755835ffb2be2b8

发布日期: 2022-08-24 16:15 修改: 2026-06-17 04:19

libpng16-16t64 CVE-2026-3713 低危 1.6.48-1+deb13u5 libpng: libpng: Heap-based buffer overflow in pnm2png allows information disclosure and denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3713

镜像层: sha256:b25b5b4e7b93b4c0b8b9a8fe94063231389989d767c227027755835ffb2be2b8

发布日期: 2026-03-08 06:16 修改: 2026-06-17 10:44

libc6 CVE-2019-1010022 低危 2.41-12+deb13u3 glibc: stack guard protection bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-1010022

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-07-15 04:15 修改: 2026-06-17 02:09

libc6 CVE-2019-1010023 低危 2.41-12+deb13u3 glibc: running ldd on malicious ELF leads to code execution because of wrong size computation

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-1010023

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-07-15 04:15 修改: 2026-06-17 02:09

libuuid1 CVE-2022-0563 低危 2.41-5 util-linux: partial disclosure of arbitrary files in chfn and chsh when compiled with libreadline

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-0563

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 2022-02-21 19:15 修改: 2026-06-17 04:20

libuuid1 CVE-2025-14104 低危 2.41-5 util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14104

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 2025-12-05 17:16 修改: 2026-06-25 04:17

libc6 CVE-2019-1010024 低危 2.41-12+deb13u3 glibc: ASLR bypass using cache of thread stack and heap

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-1010024

镜像层: sha256:3a7299f559d987305122c7669fc3643095eb0955f8ff4a38c9430d54d0b4452e

发布日期: 2019-07-15 04:15 修改: 2026-06-17 02:09

libexpat1 CVE-2026-56131 未知 2.7.1-2 libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56131

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-19 06:17 修改: 2026-06-23 20:15

libexpat1 CVE-2026-56407 未知 2.7.1-2 libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56407

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 16:28

libexpat1 CVE-2026-56408 未知 2.7.1-2 libexpat before 2.8.2 has an integer overflow in copyString.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56408

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 16:27

libuuid1 CVE-2026-53612 未知 2.41-5 [Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown]

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53612

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid1 CVE-2026-53613 未知 2.41-5 [Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53613

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid1 CVE-2026-53614 未知 2.41-5 [Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)]

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53614

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libuuid1 CVE-2026-53615 未知 2.41-5 [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53615

镜像层: sha256:38253f8df53ddff4e80c63ab44f5f224500b27ff2094bef5a22b191f364b9565

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libexpat1 CVE-2026-56409 未知 2.7.1-2 xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56409

镜像层: sha256:49bdf8e65c465162a9c999342a8e7f6e5ec4a1bfd10d3962474f3df3d7bdd763

发布日期: 2026-06-21 16:16 修改: 2026-06-23 16:21

检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×