You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
arc-consensus
8040b867295236dc9470238d435…
One-liner (summary)
Description
| Status | Completed |
|---|---|
| Checksum (MD5) | c3f9312360a103922990eaf03888d6c7 |
| Checksum (SHA-1) | ebabe044157b5c980b791c9c279659ca50a1a753 |
| Checksum (SHA-256) | 8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5 |
| Checksum (SHA-512) | e28b87b8b4edbd1335296eb6716d298ea36cf555bb1171f18713b4cd83bfe38ab8… |
| GPG Signature | |
| GPG Fingerprint | 2006bcbaea44c3d0630ff4e132ef04c02d67714a |
| Storage Region | Ohio, United States |
| Type | Binary (contains binaries and binary artifacts) |
| Uploaded At | 3 months ago |
| Uploaded By |
|
| Slug Id | arc-consensus-nrux |
| Unique Id | sVqhDBZRiuuo |
| Version (Raw) | 8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5 |
| Version (Parsed) |
|
| docker-specific metadata | |
| Image Digest | sha256:8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5 |
| Config Digest | sha256:f3d88f2e25201430a642dcbef06102eba27fbf159e8499958f88b6ed3743a6ec |
| V1 OCI Index Digest | sha256:056b34a008e0a1a657cd1fd03568a7ec3110cd0b9ad9083e9d68482e4e44933c |
| V1 Distribution (Signed) Digest | sha256:539ce7f8c85ea67b22e207bf2548109bdf32c0633029eb35d8835fcbeee56f93 |
| V2 Distribution List Digest | sha256:0549b254f85942a654852c4565d078b3597b8e0470fa456ef6ac4455e346cf01 |
| V2 Distribution Digest | sha256:1e4c432ddf53dcc8de17d957d5656834e9f706b4e059e7c6bf4d0901a6938cba |
| V1 Distribution Digest | sha256:f7e740045da8c2596a8b3caa3ac59b5387ef778b3d4f77ad6b02b271d892b629 |
| V1 OCI Digest | sha256:8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5 |
| extended metadata | |
| Manifest Type | V1 OCI |
| Architecture | arm64 |
| Config | |
| Created | 2026-06-04 14:44:00 UTC |
| Os | linux |
This package was uploaded with the following V1 OCI manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.oci.image.manifest.v1+json",
"config": {
"mediaType": "application/vnd.oci.image.config.v1+json",
"digest": "sha256:2969c7da055c9ae545bbdb6861752718f63172bd2a197369ed7ebf4368deb1db",
"size": 4982
},
"layers": [
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:36a0d76d579d99971aa6e12b2d5460703b2c27df78ecb53cfb5385c7cfc1c8ff",
"size": 83867
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e",
"size": 12481
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386",
"size": 445709
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4",
"size": 29005
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a",
"size": 67
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212",
"size": 188
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4",
"size": 123
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296",
"size": 162
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112",
"size": 80
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a",
"size": 351
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354",
"size": 314
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b",
"size": 131915
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:45fe2a39da8e9f6b385dae35ea85fa78dd4634fdc14185c905acde157167a4e1",
"size": 4964712
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:3a4001d7b1872b5352f3eb9bb01dfd05f57f8fa3ec53c1fd1940c090ca5b4a4d",
"size": 2344591
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:21cbe3884cdbb0396c8db4e6b3d1824ed28a3fd2f1ff68b902a1e4dc25aea592",
"size": 129166
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:ad3ef71fadeabd1cb426938d8788a109443599c17f473ac91e71b4b8f7fcd0a5",
"size": 741416
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:9cc52d140132c780b41914674bed78e473976a6bb9adae69364b67f6f3393c0a",
"size": 42721
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:0a304126184669a27af22f62c89725b6eefdb61cd7de6148e58160edb6c59fd2",
"size": 40326
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:644eae7fed3dba0eca1820de8428a2c0fb8544e3576d8bbb7bf4ce282718181c",
"size": 124294
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:1d41067adbb0df8653136615912383aafd6b9d6fe0dccf7b1faa030a4027c71b",
"size": 163
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:ea09bb5647e236f6247cbaa9577124eba011c9e2ef07089bd734a9ed9c9c9821",
"size": 148
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:2acf8c53b3641ad8c6260bc30d6aede9a09e5d55d93a3b7f4dbe3c76f36d19ed",
"size": 14190032
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:018c5e253b77919c7b99a5423e95ae4d256c56ff8fd39d9db6293b497a7b6be6",
"size": 4757163
}
]
}
|
Digest:
sha256:36a0d76d579d99971aa6e12b2d5460703b2c27df78ecb53cfb5385c7cfc1c8ff
Command: bazel build @bookworm//base-files/arm64:data_statusd |
81.9 KB | ||
|
Digest:
sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e
Command: bazel build @bookworm//netbase/arm64:data_statusd |
12.2 KB | ||
|
Digest:
sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386
Command: bazel build @bookworm//tzdata/arm64:data_statusd |
435.3 KB | ||
|
Digest:
sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4
Command: bazel build @bookworm//media-types/arm64:data_statusd |
28.3 KB | ||
|
Digest:
sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a
Command: bazel build //common:rootfs |
67 bytes | ||
|
Digest:
sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212
Command: bazel build //common:passwd |
188 bytes | ||
|
Digest:
sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4
Command: bazel build //common:home |
123 bytes | ||
|
Digest:
sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296
Command: bazel build //common:group |
162 bytes | ||
|
Digest:
sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112
Command: bazel build //common:tmp |
80 bytes | ||
|
Digest:
sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a
Command: bazel build //static:nsswitch |
351 bytes | ||
|
Digest:
sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354
Command: bazel build //common:os_release_debian12 |
314 bytes | ||
|
Digest:
sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b
Command: bazel build //common:cacerts_debian12_arm64 |
128.8 KB | ||
|
Digest:
sha256:45fe2a39da8e9f6b385dae35ea85fa78dd4634fdc14185c905acde157167a4e1
Command: bazel build @bookworm//libc6/arm64:data_statusd |
4.7 MB | ||
|
Digest:
sha256:3a4001d7b1872b5352f3eb9bb01dfd05f57f8fa3ec53c1fd1940c090ca5b4a4d
Command: bazel build @bookworm//libssl3/arm64:data_statusd |
2.2 MB | ||
|
Digest:
sha256:21cbe3884cdbb0396c8db4e6b3d1824ed28a3fd2f1ff68b902a1e4dc25aea592
Command: bazel build @bookworm//libgomp1/arm64:data_statusd |
126.1 KB | ||
|
Digest:
sha256:ad3ef71fadeabd1cb426938d8788a109443599c17f473ac91e71b4b8f7fcd0a5
Command: bazel build @bookworm//libstdc++6/arm64:data_statusd |
724.0 KB | ||
|
Digest:
sha256:9cc52d140132c780b41914674bed78e473976a6bb9adae69364b67f6f3393c0a
Command: bazel build @bookworm//libgcc-s1/arm64:data_statusd |
41.7 KB | ||
|
Digest:
sha256:0a304126184669a27af22f62c89725b6eefdb61cd7de6148e58160edb6c59fd2
Command: bazel build @bookworm//gcc-12-base/arm64:data_statusd |
39.4 KB | ||
|
Digest:
sha256:644eae7fed3dba0eca1820de8428a2c0fb8544e3576d8bbb7bf4ce282718181c
Command: COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt # buildkit |
121.4 KB | ||
|
Digest:
sha256:1d41067adbb0df8653136615912383aafd6b9d6fe0dccf7b1faa030a4027c71b
Command: COPY /tmp/passwd /etc/passwd # buildkit |
163 bytes | ||
|
Digest:
sha256:ea09bb5647e236f6247cbaa9577124eba011c9e2ef07089bd734a9ed9c9c9821
Command: COPY /tmp/group /etc/group # buildkit |
148 bytes | ||
|
Digest:
sha256:2acf8c53b3641ad8c6260bc30d6aede9a09e5d55d93a3b7f4dbe3c76f36d19ed
Command: COPY /tmp/arc-node-consensus /usr/local/bin/arc-node-consensus # buildkit |
13.5 MB | ||
|
Digest:
sha256:018c5e253b77919c7b99a5423e95ae4d256c56ff8fd39d9db6293b497a7b6be6
Command: COPY /tmp/arc-snapshots /usr/local/bin/arc-snapshots # buildkit |
4.5 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE [27000/tcp 29000/tcp] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER arc |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/arc-node-consensus"] |
32 bytes |
|
|
arc-consensus |
86 |
|
||
|
|
arc-consensus |
11 |
|
||
|
|
arc-consensus |
92 |
|
||
|
|
arc-consensus |
10 |
|
||
|
|
arc-consensus |
17 |
|
||
|
|
arc-consensus |
3 |
|
||
|
|
arc-consensus |
7 |
|
||
|
|
arc-consensus |
0 |
|
||
|
|
arc-consensus |
90 |
|
||
|
|
arc-consensus |
22 |
|
||
|
|
arc-consensus |
1 |
|
||
|
|
arc-consensus |
2 |
|
||
|
|
arc-consensus |
33 |
|
||
|
|
arc-consensus |
1769 |
|
||
|
|
arc-consensus |
75 |
|
||
|
|
arc-consensus |
5 |
|
||
|
|
arc-consensus |
2 |
|
||
|
|
arc-consensus |
2 |
|
Last scanned
3 months ago
Scan result
Vulnerable
Vulnerability count
13
Max. severity
Medium| Target: | sVqhDBZRiuuo.sbom-cyclonedx.json (debian 12.14) | |
| MEDIUM |
CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processingThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large widthCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodingsCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS responseThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: gcc-12-base Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2010-4756: glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressionsThe glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: cxib.net securityreason.com securityreason.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com nvd.nist.gov security.netapp.com www.cve.org |
|
| LOW |
CVE-2018-20796: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com debbugs.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.f5.com www.cve.org |
|
| LOW |
CVE-2019-1010022: glibc: stack guard protection bypassGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010023: glibc: running ldd on malicious ELF leads to code execution because of wrong size computationGNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010024: glibc: ASLR bypass using cache of thread stack and heapGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010025: glibc: information disclosure of heap addresses of pthread_created threadGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-9192: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted patternPackage Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org support.f5.com www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc-s1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgomp1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2025-27587: OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable ...OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u1 Fixed Version: References: github.com minerva.crocs.fi.muni.cz |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libstdc++6 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
These instructions assume you have setup the repository first (or read it).
To pull arc-consensus @ reference/tag sha256:8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5:
docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5
You can also pull the latest version of this image (if it exists):
docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:8040b867295236dc9470238d435e399a1f0dbc70a46994e9e4b88bf7310546d5