ghcr.io/browserless/chrome:v2.48.3 linux/amd64

ghcr.io/browserless/chrome:v2.48.3 - Trivy安全扫描结果 扫描时间: 2026-05-15 01:50
全部漏洞信息
低危漏洞:32 中危漏洞:58 高危漏洞:4 严重漏洞:10

系统OS: ubuntu 24.04 扫描引擎: Trivy 扫描时间: 2026-05-15 01:50

ghcr.io/browserless/chrome:v2.48.3 (ubuntu 24.04) (ubuntu)
低危漏洞:32 中危漏洞:52 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
bsdutils CVE-2026-27456 中危 1:2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

dpkg CVE-2026-2219 中危 1.22.6ubuntu6.5 1.22.6ubuntu6.6 It was discovered that dpkg-deb (a component of dpkg, the Debian packa ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2219

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-07 09:16 修改: 2026-03-09 15:15

git CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

git-man CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

libavahi-client3 CVE-2025-59529 中危 0.8-13ubuntu6.1 avahi: simple clients denial-of-service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59529

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2025-12-18 21:15 修改: 2026-01-16 16:50

libavahi-client3 CVE-2026-24401 中危 0.8-13ubuntu6.1 avahi: Avahi: Denial of Service via recursive CNAME record in mDNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24401

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-01-24 02:15 修改: 2026-02-12 15:58

libavahi-client3 CVE-2026-34933 中危 0.8-13ubuntu6.1 avahi: avahi-daemon: Avahi: Denial of Service via D-Bus method call

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34933

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-04-03 23:17 修改: 2026-04-13 17:26

libavahi-common-data CVE-2025-59529 中危 0.8-13ubuntu6.1 avahi: simple clients denial-of-service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59529

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2025-12-18 21:15 修改: 2026-01-16 16:50

libavahi-common-data CVE-2026-24401 中危 0.8-13ubuntu6.1 avahi: Avahi: Denial of Service via recursive CNAME record in mDNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24401

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-01-24 02:15 修改: 2026-02-12 15:58

libavahi-common-data CVE-2026-34933 中危 0.8-13ubuntu6.1 avahi: avahi-daemon: Avahi: Denial of Service via D-Bus method call

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34933

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-04-03 23:17 修改: 2026-04-13 17:26

libavahi-common3 CVE-2025-59529 中危 0.8-13ubuntu6.1 avahi: simple clients denial-of-service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59529

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2025-12-18 21:15 修改: 2026-01-16 16:50

libavahi-common3 CVE-2026-24401 中危 0.8-13ubuntu6.1 avahi: Avahi: Denial of Service via recursive CNAME record in mDNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24401

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-01-24 02:15 修改: 2026-02-12 15:58

libavahi-common3 CVE-2026-34933 中危 0.8-13ubuntu6.1 avahi: avahi-daemon: Avahi: Denial of Service via D-Bus method call

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34933

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-04-03 23:17 修改: 2026-04-13 17:26

libblkid1 CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libc-bin CVE-2026-4046 中危 2.39-0ubuntu8.7 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

libc-bin CVE-2026-4437 中危 2.39-0ubuntu8.7 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4437

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:41

libc-bin CVE-2026-4438 中危 2.39-0ubuntu8.7 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4438

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:40

libc6 CVE-2026-4046 中危 2.39-0ubuntu8.7 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

libc6 CVE-2026-4437 中危 2.39-0ubuntu8.7 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4437

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:41

libc6 CVE-2026-4438 中危 2.39-0ubuntu8.7 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4438

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:40

libcups2t64 CVE-2026-41079 中危 2.4.7-1.2ubuntu7.9 cups: CUPS: Information disclosure via crafted SNMP response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41079

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-04-24 17:16 修改: 2026-04-27 13:40

libexpat1 CVE-2025-66382 中危 2.6.1-2ubuntu0.4 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-11-28 07:15 修改: 2026-05-12 13:17

libfdisk1 CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libmount1 CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libnghttp2-14 CVE-2026-27135 中危 1.59.0-1ubuntu0.2 1.59.0-1ubuntu0.3 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27135

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-18 18:16 修改: 2026-03-23 17:51

libpixman-1-0 CVE-2023-37769 中危 0.42.2-1build1 stress-test master commit e4c878 was discovered to contain a FPE vulne ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-37769

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2023-07-17 20:15 修改: 2024-11-21 08:12

libpng16-16t64 CVE-2026-33416 中危 1.6.43-5ubuntu0.5 1.6.43-5ubuntu0.6 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33416

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-26 17:16 修改: 2026-04-02 20:28

libpng16-16t64 CVE-2026-33636 中危 1.6.43-5ubuntu0.5 1.6.43-5ubuntu0.6 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33636

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-26 17:16 修改: 2026-04-02 18:42

libpng16-16t64 CVE-2026-34757 中危 1.6.43-5ubuntu0.5 1.6.43-5ubuntu0.6 libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34757

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-04-09 15:16 修改: 2026-05-09 11:16

libpython3.12-minimal CVE-2025-13462 中危 3.12.3-1ubuntu0.13 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-12 18:16 修改: 2026-05-01 16:16

libpython3.12-minimal CVE-2026-2297 中危 3.12.3-1ubuntu0.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

libpython3.12-stdlib CVE-2025-13462 中危 3.12.3-1ubuntu0.13 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-12 18:16 修改: 2026-05-01 16:16

libpython3.12-stdlib CVE-2026-2297 中危 3.12.3-1ubuntu0.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

libsmartcols1 CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libuuid1 CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libxpm4 CVE-2026-4367 中危 1:3.5.17-1build2

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4367

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

mount CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

python3-pip CVE-2024-35195 中危 24.0+dfsg-1ubuntu1.3 requests: subsequent requests to the same host ignore cert verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-35195

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2024-05-20 21:15 修改: 2026-04-15 00:35

python3-pip CVE-2025-66418 中危 24.0+dfsg-1ubuntu1.3 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66418

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-12-05 16:15 修改: 2025-12-10 16:08

python3-pip CVE-2025-66471 中危 24.0+dfsg-1ubuntu1.3 urllib3: urllib3 Streaming API improperly handles highly compressed data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66471

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-12-05 17:16 修改: 2025-12-10 16:10

python3-pip CVE-2026-21441 中危 24.0+dfsg-1ubuntu1.3 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21441

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-01-07 22:15 修改: 2026-01-23 09:15

python3-wheel CVE-2026-24049 中危 0.42.0-2 wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24049

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-01-22 05:16 修改: 2026-02-18 14:56

python3.12 CVE-2025-13462 中危 3.12.3-1ubuntu0.13 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-12 18:16 修改: 2026-05-01 16:16

python3.12 CVE-2026-2297 中危 3.12.3-1ubuntu0.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

python3.12-minimal CVE-2025-13462 中危 3.12.3-1ubuntu0.13 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-12 18:16 修改: 2026-05-01 16:16

python3.12-minimal CVE-2026-2297 中危 3.12.3-1ubuntu0.13 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

sed CVE-2026-5958 中危 4.9-2build1 4.9-2ubuntu0.24.04.1 When sed is invoked with both -i (in-place edit) and --follow-symlinks ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5958

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-20 12:16 修改: 2026-04-20 19:05

tar CVE-2025-45582 中危 1.35+dfsg-3build1 tar: Tar path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-45582

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2025-07-11 17:15 修改: 2025-11-02 01:15

tar CVE-2026-5704 中危 1.35+dfsg-3build1 tar: tar: Hidden file injection via crafted archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5704

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-06 16:16 修改: 2026-04-22 20:08

util-linux CVE-2026-27456 中危 2.39.3-9ubuntu6.5 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

wget CVE-2021-31879 中危 1.21.4-1ubuntu4.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2021-04-29 05:15 修改: 2024-11-21 06:06

xdg-utils CVE-2025-52968 中危 1.1.3-4.1ubuntu3 xdg-utils: xdg-open bypassing SameSite=Strict

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52968

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2025-06-23 15:15 修改: 2026-04-15 00:35

libcairo-gobject2 CVE-2018-18064 低危 1.18.0-3build1 cairo: Stack-based buffer overflow via parsing of crafted WebKitGTK+ document

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-18064

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2018-10-08 18:29 修改: 2024-11-21 03:55

libcairo2 CVE-2017-7475 低危 1.18.0-3build1 cairo: NULL pointer dereference with a crafted font file

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-7475

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2017-05-19 20:29 修改: 2026-05-13 00:24

libcairo2 CVE-2018-18064 低危 1.18.0-3build1 cairo: Stack-based buffer overflow via parsing of crafted WebKitGTK+ document

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-18064

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2018-10-08 18:29 修改: 2024-11-21 03:55

libavahi-common3 CVE-2024-52616 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Predictable Transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52616

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libdw1t64 CVE-2025-1352 低危 0.190-1.1ubuntu0.1 elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1352

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-02-16 15:15 修改: 2025-11-03 20:34

libdw1t64 CVE-2025-1376 低危 0.190-1.1ubuntu0.1 elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1376

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-02-17 05:15 修改: 2025-11-04 20:21

libelf1t64 CVE-2025-1352 低危 0.190-1.1ubuntu0.1 elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1352

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-02-16 15:15 修改: 2025-11-03 20:34

login CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2024-12-26 09:15 修改: 2026-04-15 00:35

libelf1t64 CVE-2025-1376 低危 0.190-1.1ubuntu0.1 elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1376

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-02-17 05:15 修改: 2025-11-04 20:21

packagekit CVE-2022-0987 低危 1.2.8-2ubuntu1.5 PackageKit: Information Disclosure in Transaction Interface via timing

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-0987

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2022-06-28 17:15 修改: 2024-11-21 06:39

packagekit CVE-2024-0217 低危 1.2.8-2ubuntu1.5 PackageKitd: Use-After-Free in Idle Function Callback

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0217

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2024-01-03 17:15 修改: 2024-11-21 08:46

passwd CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2024-12-26 09:15 修改: 2026-04-15 00:35

polkitd CVE-2016-2568 低危 124-2ubuntu1.24.04.3 polkit: Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2568

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2017-02-13 18:59 修改: 2026-05-13 00:24

libavahi-client3 CVE-2024-52615 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Uses Constant Source Port

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52615

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libavahi-common-data CVE-2024-52615 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Uses Constant Source Port

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52615

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libgcrypt20 CVE-2024-2236 低危 1.10.3-2build1 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:538812a4b9bd45adaac2b5e5b967daa6999aa44eb110aa32ae7c69702b906475

发布日期: 2024-03-06 22:15 修改: 2026-04-15 00:35

libharfbuzz0b CVE-2026-22693 低危 8.3.0-2build2 harfbuzz: Null Pointer Dereference in harfbuzz

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22693

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2026-01-10 06:15 修改: 2026-02-18 17:49

python3-pip CVE-2026-1703 低危 24.0+dfsg-1ubuntu1.3 pip: pip: Information disclosure via path traversal when installing crafted wheel archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2026-02-02 15:16 修改: 2026-04-15 00:35

libicu74 CVE-2025-5222 低危 74.2-1ubuntu3.1 icu: Stack buffer overflow in the SRBRoot::addTag function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5222

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2025-05-27 21:15 修改: 2026-04-23 00:16

libavahi-common-data CVE-2024-52616 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Predictable Transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52616

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libavahi-client3 CVE-2024-52616 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Predictable Transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52616

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libpackagekit-glib2-18 CVE-2022-0987 低危 1.2.8-2ubuntu1.5 PackageKit: Information Disclosure in Transaction Interface via timing

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-0987

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2022-06-28 17:15 修改: 2024-11-21 06:39

libpackagekit-glib2-18 CVE-2024-0217 低危 1.2.8-2ubuntu1.5 PackageKitd: Use-After-Free in Idle Function Callback

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0217

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2024-01-03 17:15 修改: 2024-11-21 08:46

gir1.2-packagekitglib-1.0 CVE-2024-0217 低危 1.2.8-2ubuntu1.5 PackageKitd: Use-After-Free in Idle Function Callback

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0217

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2024-01-03 17:15 修改: 2024-11-21 08:46

gir1.2-packagekitglib-1.0 CVE-2022-0987 低危 1.2.8-2ubuntu1.5 PackageKit: Information Disclosure in Transaction Interface via timing

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-0987

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2022-06-28 17:15 修改: 2024-11-21 06:39

libavahi-common3 CVE-2024-52615 低危 0.8-13ubuntu6.1 avahi: Avahi Wide-Area DNS Uses Constant Source Port

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52615

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2024-11-21 21:15 修改: 2026-04-15 00:35

libcairo-gobject2 CVE-2017-7475 低危 1.18.0-3build1 cairo: NULL pointer dereference with a crafted font file

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-7475

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2017-05-19 20:29 修改: 2026-05-13 00:24

libpolkit-agent-1-0 CVE-2016-2568 低危 124-2ubuntu1.24.04.3 polkit: Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2568

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2017-02-13 18:59 修改: 2026-05-13 00:24

libpolkit-gobject-1-0 CVE-2016-2568 低危 124-2ubuntu1.24.04.3 polkit: Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2568

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2017-02-13 18:59 修改: 2026-05-13 00:24

xdg-utils CVE-2022-4055 低危 1.1.3-4.1ubuntu3 xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-4055

镜像层: sha256:fd89d03daedbf6cd01d218bbced03a605f18d7933538b52651d5743c9d701769

发布日期: 2022-11-19 00:15 修改: 2025-04-29 19:15

xserver-common CVE-2023-5574 低危 2:21.1.12-1ubuntu1.5 xorg-x11-server: Use-after-free bug in DamageDestroy

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5574

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2023-10-25 20:15 修改: 2024-11-21 08:42

xvfb CVE-2023-5574 低危 2:21.1.12-1ubuntu1.5 xorg-x11-server: Use-after-free bug in DamageDestroy

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5574

镜像层: sha256:73e8c553c2d68249066680db1267c2b66167e2c8bb0e6148ed89b19d11a6d7f0

发布日期: 2023-10-25 20:15 修改: 2024-11-21 08:42

Node.js (node-pkg)
低危漏洞:0 中危漏洞:6 高危漏洞:4 严重漏洞:10
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
vm2 CVE-2026-24118 严重 3.10.5 3.11.0 VM2 Sandbox Breakout Through __lookupGetter__

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24118

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-04 17:16 修改: 2026-05-08 19:30

vm2 CVE-2026-24781 严重 3.10.5 3.11.0 vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24781

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-04 17:16 修改: 2026-05-08 19:29

vm2 CVE-2026-26332 严重 3.10.5 3.11.0 VM2 Has a Sandbox Escape Issue via SuppressedError

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26332

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-04 17:16 修改: 2026-05-06 12:24

vm2 CVE-2026-43997 严重 3.10.5 3.11.0 vm2 Access to Host Object Enables Sandbox Escape

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43997

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-43999 严重 3.10.5 3.11.0 vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43999

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44005 严重 3.10.5 3.11.0 vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44005

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44006 严重 3.10.5 3.11.0 vm2 has a Sandbox Escape Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44006

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44007 严重 3.10.5 3.11.1 vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44007

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44008 严重 3.10.5 3.11.2 vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44008

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44009 严重 3.10.5 3.11.2 vm2 has Sandbox Breakout Through Null Proto Exception

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44009

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

basic-ftp CVE-2026-44240 高危 5.3.0 5.3.1 basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44240

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-12 21:16 修改: 2026-05-12 21:16

vm2 CVE-2026-43998 高危 3.10.5 3.11.0 vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43998

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44001 高危 3.10.5 3.11.0 vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44001

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44004 高危 3.10.5 3.11.0 vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44004

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

ip-address CVE-2026-42338 中危 10.1.0 10.1.1 ip-address has XSS in Address6 HTML-emitting methods

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42338

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-12 20:16 修改: 2026-05-12 20:16

ip-address CVE-2026-42338 中危 10.1.0 10.1.1 ip-address has XSS in Address6 HTML-emitting methods

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42338

镜像层: sha256:d202bd746fe36e25e6cc4d41f53c5546a83c70f62c611a5616b9e9e92243d83c

发布日期: 2026-05-12 20:16 修改: 2026-05-12 20:16

vm2 CVE-2026-44000 中危 3.10.5 3.11.0 vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44000

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44002 中危 3.10.5 3.11.0 vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44002

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 CVE-2026-44003 中危 3.10.5 3.11.0 vm2's Transformer Fast-Path Bypass Exposes Internal State Variable

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44003

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

vm2 GHSA-2cm2-m3w5-gp2f 中危 3.10.5 3.11.2 vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`

漏洞详情: https://github.com/advisories/GHSA-2cm2-m3w5-gp2f

镜像层: sha256:b64f9e9cb07672000f11706807fe01941a519fb3ba846835c0801c8374548982

发布日期: 2026-05-08 16:22 修改: 2026-05-08 16:22

/etc/ssh/ssh_host_ecdsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_ed25519_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_rsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息