搜索结果
关于「podman」的漏洞数据
| AVD编号 | 漏洞名称 | 漏洞类型 | 披露时间 | 漏洞状态 |
|---|---|---|---|---|
| AVD-2026-39822 | 通过操作系统中的符号链接和尾部斜杠进行根转义 (CVE-2026-39822) | 2026-07-09 | ||
| AVD-2026-57231 | Podman:格式错误的图像可能会诱使 podman 将主机环境变量泄漏到容器中 (CVE-2026-57231) | 2026-06-27 | ||
| AVD-2026-55686 | Podman:WORKDIR 符号链接遍历漏洞 (CVE-2026-55686) | 2026-06-27 | ||
| AVD-2026-27136 | 调用重复属性可能会导致 golang.org/x/net/html 中的 XSS (CVE-2026-27136) | 2026-05-23 | ||
| AVD-2026-25681 | 在 golang.org/x/net/html 的 DOCTYPE 节点中调用字符引用的错误处理 (CVE-2026-25681) | 2026-05-23 | ||
| AVD-2026-42508 | 通过 golang.org/x/crypto/ssh/knownhosts 中未强制执行的 @revoked 状态调用身份验证绕过 (CVE-2026-42508) | 2026-05-22 | ||
| AVD-2026-39835 | 在 golang.org/x/crypto/ssh 中的 CheckHostKey/Authenticate 期间调用服务器恐慌 (CVE-2026-39835) | 2026-05-22 | ||
| AVD-2026-39832 | 在 golang.org/x/crypto/ssh/agent 中转发密钥时调用代理约束被删除 (CVE-2026-39832) | 2026-05-22 | ||
| AVD-2026-39830 | 调用客户端可能会因 golang.org/x/crypto/ssh 中的意外响应而导致服务器死锁 (CVE-2026-39830) | 2026-05-22 | ||
| AVD-2026-33414 | Podman 4.8.0-5.8.1 HyperV命令注入(CVE-2026-33414) | 2026-04-15 | ||
| AVD-2026-32281 | Google Go 安全漏洞(CVE-2026-32281) | 2026-04-08 | ||
| AVD-2026-34986 | go-jose JWE解密引发Panic拒绝服务漏洞(CVE-2026-34986) | 2026-04-07 | ||
| AVD-2025-61728 | Google Go 安全漏洞(CVE-2025-61728) | 2026-01-29 | ||
| AVD-2025-47913 | golang.org/x/crypto/ssh/agent 中可能存在拒绝服务 (CVE-2025-47913) | 2025-11-14 | ||
| AVD-2025-52881 | Runc procfs 容器逃逸漏洞 (CVE-2025-52881) | 2025-11-07 | ||
| AVD-2025-9566 | Podman:Podman Kube Play命令可能会覆盖主机文件(CVE-2025-9566) | 2025-09-06 | ||
| AVD-2025-58058 | github.com/ulikunitz/xz 在解码损坏的多个 LZMA 存档时泄漏内存 (CVE-2025-58058) | 2025-08-29 | ||
| AVD-2025-47907 | 从数据库/SQL中的行返回的不正确结果(CVE-2025-47907) | 2025-08-08 | ||
| AVD-2025-6032 | Podman:Podman缺少TLS验证(CVE-2025-6032) | 2025-06-24 | ||
| AVD-2025-22869 | golang.org/x/crypto的潜在拒绝服务(CVE-2025-22869) | 2025-02-26 | ||
| AVD-2024-11218 | Podman:buildah:在构建恶意容器文件时使用 --jobs=2 和竞争条件导致容器突破(CVE-2024-11218) | 2025-01-22 | ||
| AVD-2024-9676 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2024-9676) | 2024-10-15 | ||
| AVD-2024-9675 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2024-9675) | 2024-10-09 | ||
| AVD-2024-9341 | Improper Link Resolution Before File Access ('Link Following') (CVE-2024-9341) | 2024-10-01 | ||
| AVD-2024-9407 | Improper Input Validation (CVE-2024-9407) | 2024-10-01 | ||
| AVD-2024-9355 | Use of Uninitialized Variable (CVE-2024-9355) | 2024-09-30 | ||
| AVD-2024-34155 | go/parser 中所有 Parse 函数的堆栈耗尽 (CVE-2024-34155) | 2024-09-07 | ||
| AVD-2024-34158 | go/build/constraint 中 Parse 的堆栈耗尽(CVE-2024-34158) | 2024-09-07 | ||
| AVD-2024-3056 | Uncontrolled Resource Consumption (CVE-2024-3056) | 2024-07-25 | ||
| AVD-2024-37298 | 由于稀疏切片反序列化而导致的潜在内存耗尽攻击(CVE-2024-37298) | 2024-07-02 |