Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, Nix, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public eventstore eventstore (Kurrent) / eventstore-preview
Public Previews. Non-production.

Docker logo eventstoredb-oss  23.10.8-alpha-arm64v8

One-liner (summary)

A certifiably-awesome package curated by cicd, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by cicd, hosted by Cloudsmith.

License

Unknown

Size

98.6 MB

Downloads

12

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 009e72f8a3fac138b547cde32314ddb0
Checksum (SHA-1) 7c0b6eb9e9efb05f403b62d6163854af02d782e2
Checksum (SHA-256) 47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a
Checksum (SHA-512) 4a16197dc7734f326ff0724c6ba954727bd2aac55c000b034340daaa7a524447c4…
GPG Signature
GPG Fingerprint 69f6921fcf1795d23d007088efec87a4f8f5849d
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 9 months, 3 weeks ago
Uploaded By Uploaded by cicd
Slug Id eventstoredb-oss-ji0k
Unique Id bnSSSeBVNGv8
Version (Raw) 23.10.8-alpha-arm64v8
Version (Parsed)
  • Major: 23
  • Minor: 10
  • Patch: 8
  • Pre (Str): alphaarmv
  • Pre (Num Array): 64.8
  • Type: SemVer (Strict)
Orig Version (Raw) 47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a
Orig Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a
Config Digest sha256:c77a120f85b795f316640d331648f960366e771b5133289f5c0d96412734737a
V1 OCI Index Digest sha256:ccccd16af1b8007e47c6511f5795ab7573897d87719ccec9690e19137e100f35
V1 Distribution (Signed) Digest sha256:eb7f188998038c6944fe6a47041695834d3e4c029ba393c3c3504af2e8780dac
V1 OCI Digest sha256:e34195715d6e1688a3264904ead04d7054729577953eb7d2a18227e1b7eaee7e
V2 Distribution List Digest sha256:935d6c4e0042a2f512bc609ee36c4f953c91f83a8e49e07c536127c6c81a1cd2
V1 Distribution Digest sha256:8df9217150ab06f2c3ca9f0a55be0abfad457528800b6ef7afac90c390b139a7
V2 Distribution Digest sha256:47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2025-11-04 17:10:57 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{
   "schemaVersion": 2,
   "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
   "config": {
      "mediaType": "application/vnd.docker.container.image.v1+json",
      "size": 6149,
      "digest": "sha256:fd6f4b15074ad136a6fb8b6f23a40ca120fd09e4eb1dd76d401da653373c9226"
   },
   "layers": [
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 28430582,
         "digest": "sha256:2dc13b9cae25073cd9f56d07a48f0b9cda39dc94615ea7e3fab2ca58906fabce"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 16630175,
         "digest": "sha256:96c1ab6367fa314c979cd2a5a7aff8e2f755d26de43f1273d8714f757699d677"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 3549,
         "digest": "sha256:c4950d0105a2ce2188735dbbd6a0f93418751bf6662aebc2faf4392616c18136"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 2035206,
         "digest": "sha256:082257c271d74de38be50336c7179b3644cf7a7ab1993ec817d94170c1c25f6d"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 117,
         "digest": "sha256:e4a35faa3c484aa6d820aa9380c15ef2a3ff5d2cb113fab2abb9ad9a2a3f9039"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 1885,
         "digest": "sha256:95bb2aeae11b8129a30880aa5de1ba7acdcbf5661e8c971cea8e3dde55b2aa50"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 56268591,
         "digest": "sha256:b1fd718f259ded70f50fe2e3dd9001aca486e066eb3af9b6f40f2534661e25c4"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 193,
         "digest": "sha256:3c563ba1e900d0320c254da09fbc5bcc94a653d426ac99f84b00767c2f9a0aa7"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 190,
         "digest": "sha256:6b01d570b7834dbceaefaf4cdaed7ed123690bc17eb5deba5df3fc54ca1bf6dc"
      }
   ]
}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.ref.name=ubuntu
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=22.04
32 bytes
Digest: sha256:2dc13b9cae25073cd9f56d07a48f0b9cda39dc94615ea7e3fab2ca58906fabce
Command: /bin/sh -c #(nop) ADD file:2e0e653363da35febc0204e69cb713c0d1497720522f79d3d531980a7f291a39 in /
27.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV APP_UID=1654 ASPNETCORE_HTTP_PORTS=8080 DOTNET_RUNNING_IN_CONTAINER=true
32 bytes
Digest: sha256:96c1ab6367fa314c979cd2a5a7aff8e2f755d26de43f1273d8714f757699d677
Command: RUN /bin/sh -c apt-get update && apt-get install -y --no-install-recommends ca-certificates libc6 libgcc-s1 libicu70 libssl3 libstdc++6 tzdata zlib1g && rm -rf /var/lib/apt/lists/* # buildkit
15.9 MB
Digest: sha256:c4950d0105a2ce2188735dbbd6a0f93418751bf6662aebc2faf4392616c18136
Command: RUN /bin/sh -c groupadd --gid=$APP_UID app && useradd --no-log-init --uid=$APP_UID --gid=$APP_UID --create-home app # buildkit
3.5 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG RUNTIME=linux-x64
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1000
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1000
32 bytes
Digest: sha256:082257c271d74de38be50336c7179b3644cf7a7ab1993ec817d94170c1c25f6d
Command: RUN |3 RUNTIME=linux-arm64 UID=1000 GID=1000 /bin/sh -c if [[ "${RUNTIME}" = "linux-musl-x64" ]]; then apk update && apk add --no-cache curl; else apt update && apt install -y curl && rm -rf /var/lib/apt/lists/*; fi # buildkit
1.9 MB
Digest: sha256:e4a35faa3c484aa6d820aa9380c15ef2a3ff5d2cb113fab2abb9ad9a2a3f9039
Command: WORKDIR /opt/eventstore
117 bytes
Digest: sha256:95bb2aeae11b8129a30880aa5de1ba7acdcbf5661e8c971cea8e3dde55b2aa50
Command: RUN |3 RUNTIME=linux-arm64 UID=1000 GID=1000 /bin/sh -c addgroup --gid ${GID} "eventstore" && adduser --disabled-password --gecos "" --ingroup "eventstore" --no-create-home --uid ${UID} "eventstore" # buildkit
1.8 KB
Digest: sha256:b1fd718f259ded70f50fe2e3dd9001aca486e066eb3af9b6f40f2534661e25c4
Command: COPY /publish ./ # buildkit
53.7 MB
Digest: sha256:3c563ba1e900d0320c254da09fbc5bcc94a653d426ac99f84b00767c2f9a0aa7
Command: RUN |3 RUNTIME=linux-arm64 UID=1000 GID=1000 /bin/sh -c mkdir -p /var/lib/eventstore && mkdir -p /var/log/eventstore && mkdir -p /etc/eventstore && chown -R eventstore:eventstore /var/lib/eventstore /var/log/eventstore /etc/eventstore # buildkit
193 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER eventstore
32 bytes
Digest: sha256:6b01d570b7834dbceaefaf4cdaed7ed123690bc17eb5deba5df3fc54ca1bf6dc
Command: RUN |3 RUNTIME=linux-arm64 UID=1000 GID=1000 /bin/sh -c printf "NodeIp: 0.0.0.0\nReplicationIp: 0.0.0.0" >> /etc/eventstore/eventstore.conf # buildkit
190 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/lib/eventstore /var/log/eventstore]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1112/tcp:{} 1113/tcp:{} 2113/tcp:{}]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: HEALTHCHECK &{["CMD-SHELL" "curl --fail --insecure https://localhost:2113/health/live || curl --fail http://localhost:2113/health/live || exit 1"] "5s" "5s" "0s" '\x18'}
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/opt/eventstore/EventStore.ClusterNode"]
32 bytes

Last scanned

9 months, 3 weeks ago

Scan result

Vulnerable

Vulnerability count

18

Max. severity

Medium
Target: bnSSSeBVNGv8.sbom-cyclonedx.json (ubuntu 22.04)
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-modules
Installed Version: 1.4.0-11ubuntu2.6
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-modules-bin
Installed Version: 1.4.0-11ubuntu2.6
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-runtime
Installed Version: 1.4.0-11ubuntu2.6
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam0g
Installed Version: 1.4.0-11ubuntu2.6
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-45582: tar: Tar path traversal

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each "tar xf" in its Security Rules of Thumb; however, third-party advice leads users to run "tar xf" more than once into the same directory.

Package Name: tar
Installed Version: 1.34+dfsg-1ubuntu0.1.22.04.2
Fixed Version:

References: www.openwall.com access.redhat.com github.com lists.gnu.org nvd.nist.gov www.cve.org www.gnu.org www.gnu.org www.gnu.org www.gnu.org
LOW

CVE-2016-2781: coreutils: Non-privileged session can escape to the parent session in chroot

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Package Name: coreutils
Installed Version: 8.32-4.1ubuntu1.2
Fixed Version:

References: seclists.org www.openwall.com www.openwall.com access.redhat.com lists.apache.org lore.kernel.org mirrors.edge.kernel.org nvd.nist.gov www.cve.org
LOW

CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HT ...

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

Package Name: curl
Installed Version: 7.81.0-1ubuntu1.21
Fixed Version:

References: curl.se curl.se hackerone.com nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2025-9086: curl: libcurl: Curl out of bounds read for cookie path

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path='/'`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

Package Name: curl
Installed Version: 7.81.0-1ubuntu1.21
Fixed Version:

References: access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: gcc-12-base
Installed Version: 12.3.0-1ubuntu1~22.04.2
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2022-3219: gnupg: denial of service issue (resource consumption) using compressed packets

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

Package Name: gpgv
Installed Version: 2.2.27-3ubuntu2.4
Fixed Version:

References: access.redhat.com bugzilla.redhat.com dev.gnupg.org dev.gnupg.org marc.info nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HT ...

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

Package Name: libcurl4
Installed Version: 7.81.0-1ubuntu1.21
Fixed Version:

References: curl.se curl.se hackerone.com nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2025-9086: curl: libcurl: Curl out of bounds read for cookie path

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path='/'`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

Package Name: libcurl4
Installed Version: 7.81.0-1ubuntu1.21
Fixed Version:

References: access.redhat.com curl.se curl.se github.com hackerone.com nvd.nist.gov www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libgcc-s1
Installed Version: 12.3.0-1ubuntu1~22.04.2
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2024-2236: libgcrypt: vulnerable to Marvin Attack

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Package Name: libgcrypt20
Installed Version: 1.9.4-3ubuntu3
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com dev.gnupg.org errata.almalinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org
LOW

CVE-2025-5222: icu: Stack buffer overflow in the SRBRoot::addTag function

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

Package Name: libicu70
Installed Version: 70.1-2
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: libncurses6
Installed Version: 6.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: libncursesw6
Installed Version: 6.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

Package Name: libpcre2-8-0
Installed Version: 10.39-3ubuntu0.1
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2017-11164: pcre: OP_KETRMAX feature in the match function in pcre_exec.c

In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.

Package Name: libpcre3
Installed Version: 2:8.39-13ubuntu0.22.04.1
Fixed Version:

References: openwall.com www.openwall.com www.openwall.com www.securityfocus.com access.redhat.com lists.apache.org nvd.nist.gov www.cve.org
LOW

CVE-2025-8114: : NULL Pointer Dereference in libssh KEX Session ID Calculation

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

Package Name: libssh-4
Installed Version: 0.9.6-2ubuntu0.22.04.5
Fixed Version:

References: access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org www.libssh.org
LOW

CVE-2024-41996: openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.

Package Name: libssl3
Installed Version: 3.0.2-0ubuntu1.20
Fixed Version:

References: access.redhat.com dheatattack.gitlab.io dheatattack.gitlab.io gist.github.com github.com github.com nvd.nist.gov openssl-library.org www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libstdc++6
Installed Version: 12.3.0-1ubuntu1~22.04.2
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2023-7008: systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.

Package Name: libsystemd0
Installed Version: 249.11-0ubuntu3.17
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com lists.fedoraproject.org lists.fedoraproject.org nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: libtinfo6
Installed Version: 6.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2023-7008: systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.

Package Name: libudev1
Installed Version: 249.11-0ubuntu3.17
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com lists.fedoraproject.org lists.fedoraproject.org nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2022-4899: zstd: mysql: buffer overrun in util.c

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

Package Name: libzstd1
Installed Version: 1.4.8+dfsg-3build1
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com errata.almalinux.org github.com github.com github.com github.com github.com linux.oracle.com linux.oracle.com lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org nvd.nist.gov security.netapp.com security.netapp.com www.cve.org
LOW

CVE-2023-29383: shadow: Improper input validation in shadow-utils package utility chfn

In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.

Package Name: login
Installed Version: 1:4.8.1-2ubuntu2.2
Fixed Version:

References: access.redhat.com github.com github.com lists.debian.org nvd.nist.gov www.cve.org www.trustwave.com www.trustwave.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.8.1-2ubuntu2.2
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-base
Installed Version: 6.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-bin
Installed Version: 6.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2024-41996: openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.

Package Name: openssl
Installed Version: 3.0.2-0ubuntu1.20
Fixed Version:

References: access.redhat.com dheatattack.gitlab.io dheatattack.gitlab.io gist.github.com github.com github.com nvd.nist.gov openssl-library.org www.cve.org
LOW

CVE-2023-29383: shadow: Improper input validation in shadow-utils package utility chfn

In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.

Package Name: passwd
Installed Version: 1:4.8.1-2ubuntu2.2
Fixed Version:

References: access.redhat.com github.com github.com lists.debian.org nvd.nist.gov www.cve.org www.trustwave.com www.trustwave.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.8.1-2ubuntu2.2
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org

You can embed a badge in another website that shows this or the latest version of this package.

To embed the badge for this specific package version, use the following:

[![This version of 'eventstoredb-oss' @ Cloudsmith](https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/23.10.8-alpha-arm64v8/a=arm64;xpo=linux/?render=true)](https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a/a=arm64;xpo=linux/)
|This version of 'eventstoredb-oss' @ Cloudsmith|
.. |This version of 'eventstoredb-oss' @ Cloudsmith| image:: https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/23.10.8-alpha-arm64v8/a=arm64;xpo=linux/?render=true
   :target: https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a/a=arm64;xpo=linux/
image::https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/23.10.8-alpha-arm64v8/a=arm64;xpo=linux/?render=true[link="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a/a=arm64;xpo=linux/",title="This version of 'eventstoredb-oss' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/47211c951448e7060cc0c7436e823dc0f3915ab73d95a14674736a1a8ead548a/a=arm64;xpo=linux/"><img src="https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/23.10.8-alpha-arm64v8/a=arm64;xpo=linux/?render=true" alt="This version of 'eventstoredb-oss' @ Cloudsmith" /></a>

rendered as: This version of 'eventstoredb-oss' @ Cloudsmith

To embed the badge for the latest package version, use the following:

[![Latest version of 'eventstoredb-oss' @ Cloudsmith](https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/?render=true&show_latest=true)](https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/)
|Latest version of 'eventstoredb-oss' @ Cloudsmith|
.. |Latest version of 'eventstoredb-oss' @ Cloudsmith| image:: https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/?render=true&show_latest=true
   :target: https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/
image::https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/?render=true&show_latest=true[link="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/",title="Latest version of 'eventstoredb-oss' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/"><img src="https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-oss/latest/a=arm64;xpo=linux/?render=true&show_latest=true" alt="Latest version of 'eventstoredb-oss' @ Cloudsmith" /></a>

rendered as: Latest version of 'eventstoredb-oss' @ Cloudsmith

These instructions assume you have setup the repository first (or read it).

To pull eventstoredb-oss @ reference/tag 23.10.8-alpha-arm64v8:

docker pull docker.eventstore.com/eventstore-preview/eventstoredb-oss:23.10.8-alpha-arm64v8

You can also pull the latest version of this image (if it exists):

docker pull docker.eventstore.com/eventstore-preview/eventstoredb-oss:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.eventstore.com/eventstore-preview/eventstoredb-oss:23.10.8-alpha-arm64v8
Top