Skip to content

Security Check

Security Check #56

Triggered via schedule January 17, 2025 04:40
Status Success
Total duration 32s
Artifacts

security.yml

on: schedule
Matrix: scan
Fit to window
Zoom out
Zoom in

Annotations

60 errors, 70 warnings, and 30 notices
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-50055 - HIGH severity - kernel: driver core: bus: Fix double free in driver API bus_register() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-50055 - HIGH severity - kernel: driver core: bus: Fix double free in driver API bus_register() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-50121 - HIGH severity - kernel: nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-50121 - HIGH severity - kernel: nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-52356 - HIGH severity - libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service vulnerability in libtiff6
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-7006 - HIGH severity - libtiff: NULL pointer dereference in tif_dirinfo.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-52356 - HIGH severity - libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-7006 - HIGH severity - libtiff: NULL pointer dereference in tif_dirinfo.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-52356 - HIGH severity - libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-7006 - HIGH severity - libtiff: NULL pointer dereference in tif_dirinfo.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-0
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-bin
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-52533 - HIGH severity - glib: buffer overflow in set_connect_msg() vulnerability in libglib2.0-data
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-7592 - HIGH severity - cpython: python: Uncontrolled CPU resource consumption when in http.cookies module vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-47745 - HIGH severity - kernel: mm: call the security_mmap_file() LSM hook in remap_file_pages() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-49861 - HIGH severity - kernel: bpf: Fix helper writes to read-only maps vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-49996 - HIGH severity - kernel: cifs: Fix buffer overflow when parsing NFS reparse points vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-50055 - HIGH severity - kernel: driver core: bus: Fix double free in driver API bus_register() vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-50121 - HIGH severity - kernel: nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.3-fpm-bookworm)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.3-fpm-bookworm)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2022-49034 - MEDIUM severity - kernel: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2022-49034 - MEDIUM severity - kernel: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2023-52916 - MEDIUM severity - kernel: media: aspeed: Fix memory overwrite if timing is 1600x900 vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2023-52916 - MEDIUM severity - kernel: media: aspeed: Fix memory overwrite if timing is 1600x900 vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-26595 - MEDIUM severity - kernel: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-26595 - MEDIUM severity - kernel: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-52339 - MEDIUM severity - In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can ... vulnerability in libebml5
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-25433 - MEDIUM severity - libtiff: Buffer Overflow via /libtiff/tools/tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2023-26965 - MEDIUM severity - libtiff: heap-based use after free via a crafted TIFF image in loadImage() in tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-52339 - MEDIUM severity - In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can ... vulnerability in libebml5
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-25433 - MEDIUM severity - libtiff: Buffer Overflow via /libtiff/tools/tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2023-26965 - MEDIUM severity - libtiff: heap-based use after free via a crafted TIFF image in loadImage() in tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-52339 - MEDIUM severity - In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can ... vulnerability in libebml5
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-25433 - MEDIUM severity - libtiff: Buffer Overflow via /libtiff/tools/tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2023-26965 - MEDIUM severity - libtiff: heap-based use after free via a crafted TIFF image in loadImage() in tiffcrop.c vulnerability in libtiff6
scan (ghcr.io/toshy/php:fpm-bookworm)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:fpm-bookworm)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2023-27043 - MEDIUM severity - python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-6923 - MEDIUM severity - cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-9287 - MEDIUM severity - python: Virtual environment (venv) activation scripts don't quote paths vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2022-49034 - MEDIUM severity - kernel: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2023-52916 - MEDIUM severity - kernel: media: aspeed: Fix memory overwrite if timing is 1600x900 vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-26595 - MEDIUM severity - kernel: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.3-fpm-bookworm-ffmpeg)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
scan (ghcr.io/toshy/php:8.3-fpm-bookworm-ffmpeg)
Dockerfile not provided. Skipping sarif scan result.
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:8.1-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:8.2-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:8.1-fpm-bookworm-ffmpeg)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-minimal
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in libpython3.11-stdlib
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-53161 - LOW severity - kernel: EDAC/bluefield: Fix potential integer overflow vulnerability in linux-libc-dev
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11
scan (ghcr.io/toshy/php:fpm-bookworm)
CVE-2024-11168 - LOW severity - python: Improper validation of IPv6 and IPvFuture addresses vulnerability in python3.11-minimal