{"grype_matches":[{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-05","epss":0.8833,"percentile":0.99768}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9445","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9445","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-06-27","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"risk":41.12775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9445"},"relatedVulnerabilities":[{"id":"CVE-2017-9445","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"urls":["http://openwall.com/lists/oss-security/2017/06/27/8","http://www.securityfocus.com/bid/99302","http://www.securitytracker.com/id/1038806","https://launchpad.net/bugs/1695546"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9445","description":"In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9445","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9445","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-06-27","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"risk":41.12775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9445"},"relatedVulnerabilities":[{"id":"CVE-2017-9445","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"urls":["http://openwall.com/lists/oss-security/2017/06/27/8","http://www.securityfocus.com/bid/99302","http://www.securitytracker.com/id/1038806","https://launchpad.net/bugs/1695546"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9445","description":"In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-9445","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9445","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-06-27","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"risk":41.12775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9445"},"relatedVulnerabilities":[{"id":"CVE-2017-9445","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"urls":["http://openwall.com/lists/oss-security/2017/06/27/8","http://www.securityfocus.com/bid/99302","http://www.securitytracker.com/id/1038806","https://launchpad.net/bugs/1695546"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9445","description":"In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9445","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9445","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-06-27","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"risk":41.12775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9445"},"relatedVulnerabilities":[{"id":"CVE-2017-9445","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9445","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9445","date":"2026-10-05","epss":0.54837,"percentile":0.98998}],"urls":["http://openwall.com/lists/oss-security/2017/06/27/8","http://www.securityfocus.com/bid/99302","http://www.securitytracker.com/id/1038806","https://launchpad.net/bugs/1695546"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9445","description":"In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-25032","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-25032","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-05","epss":0.51733,"percentile":0.98917}],"risk":25.8665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-25032"},"relatedVulnerabilities":[{"id":"CVE-2018-25032","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-05","epss":0.51733,"percentile":0.98917}],"urls":["http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","http://www.openwall.com/lists/oss-security/2022/03/25/2","http://www.openwall.com/lists/oss-security/2022/03/26/1","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531","https://github.com/madler/zlib/compare/v1.2.11...v1.2.12","https://github.com/madler/zlib/issues/605","https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html","https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/","https://security.gentoo.org/glsa/202210-42","https://security.netapp.com/advisory/ntap-20220526-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5111","https://www.openwall.com/lists/oss-security/2022/03/24/1","https://www.openwall.com/lists/oss-security/2022/03/28/1","https://www.openwall.com/lists/oss-security/2022/03/28/3","https://www.oracle.com/security-alerts/cpujul2022.html","https://cert-portal.siemens.com/productcert/html/ssa-333517.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-419740.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-565386.html","https://cert-portal.siemens.com/productcert/html/ssa-942865.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-25032","description":"zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches."}]},{"artifact":{"id":"bbf8a50c5579e908","cpes":["cpe:2.3:a:libdb5.3:libdb5.3:5.3.28-11:*:*:*:*:*:*:*"],"name":"libdb5.3","purl":"pkg:deb/ubuntu/libdb5.3@5.3.28-11?arch=amd64&distro=ubuntu-16.04&upstream=db5.3","type":"deb","version":"5.3.28-11","language":"","licenses":["sha256:b3bbc6fbb3f2a0e6a487e953eb8c3cc4bdb6f4150f7f51d20b1e9a3c8ef92d3d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdb5.3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libdb5.3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"db5.3"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.3.28-11ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-8457","versionConstraint":"< 5.3.28-11ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"db5.3","version":"5.3.28-11"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-8457","fix":{"state":"fixed","versions":["5.3.28-11ubuntu0.2"],"available":[{"date":"2019-06-04","kind":"advisory","version":"5.3.28-11ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-05","epss":0.45426,"percentile":0.98756}],"risk":22.713,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-8457"},"relatedVulnerabilities":[{"id":"CVE-2019-8457","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Secondary","source":"cve@checkpoint.com"},{"cve":"CVE-2019-8457","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8457","date":"2026-10-05","epss":0.45426,"percentile":0.98756}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG6TJ263RXH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH3HQOF4G3M/","https://security.netapp.com/advisory/ntap-20190606-0002/","https://usn.ubuntu.com/4004-1/","https://usn.ubuntu.com/4004-2/","https://usn.ubuntu.com/4019-1/","https://usn.ubuntu.com/4019-2/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.sqlite.org/releaselog/3_28_0.html","https://www.sqlite.org/src/info/90acdbfce9c08858"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-8457","description":"SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15908","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15908","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"risk":11.816500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15908"},"relatedVulnerabilities":[{"id":"CVE-2017-15908","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"urls":["http://www.securityfocus.com/bid/101600","http://www.securitytracker.com/id/1039662","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351","https://github.com/systemd/systemd/pull/7184","https://usn.ubuntu.com/3558-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15908","description":"In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15908","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15908","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"risk":11.816500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15908"},"relatedVulnerabilities":[{"id":"CVE-2017-15908","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"urls":["http://www.securityfocus.com/bid/101600","http://www.securitytracker.com/id/1039662","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351","https://github.com/systemd/systemd/pull/7184","https://usn.ubuntu.com/3558-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15908","description":"In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-15908","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15908","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"risk":11.816500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15908"},"relatedVulnerabilities":[{"id":"CVE-2017-15908","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"urls":["http://www.securityfocus.com/bid/101600","http://www.securitytracker.com/id/1039662","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351","https://github.com/systemd/systemd/pull/7184","https://usn.ubuntu.com/3558-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15908","description":"In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15908","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15908","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"risk":11.816500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15908"},"relatedVulnerabilities":[{"id":"CVE-2017-15908","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15908","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15908","date":"2026-10-05","epss":0.23633,"percentile":0.97751}],"urls":["http://www.securityfocus.com/bid/101600","http://www.securitytracker.com/id/1039662","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351","https://github.com/systemd/systemd/pull/7184","https://usn.ubuntu.com/3558-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15908","description":"In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service."}]},{"artifact":{"id":"09f678f8187b6d3f","cpes":["cpe:2.3:a:apt:apt:1.1.10:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/ubuntu/apt@1.1.10?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.29ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.2.29ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.2.29ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.2.29ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-05","epss":0.14555,"percentile":0.96552}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-05","epss":0.14555,"percentile":0.96552}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"aba0f26b4d9c7fe4","cpes":["cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*"],"name":"libapt-pkg5.0","purl":"pkg:deb/ubuntu/libapt-pkg5.0@1.1.10?arch=amd64&distro=ubuntu-16.04&upstream=apt","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg5.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapt-pkg5.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.29ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3462","versionConstraint":"< 1.2.29ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3462","fix":{"state":"fixed","versions":["1.2.29ubuntu0.1"],"available":[{"date":"2019-01-22","kind":"advisory","version":"1.2.29ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-05","epss":0.14555,"percentile":0.96552}],"risk":10.916250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3462"},"relatedVulnerabilities":[{"id":"CVE-2019-3462","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-3462","date":"2026-10-05","epss":0.14555,"percentile":0.96552}],"urls":["http://www.securityfocus.com/bid/106690","https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html","https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html","https://security.netapp.com/advisory/ntap-20190125-0002/","https://usn.ubuntu.com/3863-1/","https://usn.ubuntu.com/3863-2/","https://www.debian.org/security/2019/dsa-4371"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3462","description":"Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1000001","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1000001","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"risk":10.025999999999998,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000001"},"relatedVulnerabilities":[{"id":"CVE-2018-1000001","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"urls":["http://seclists.org/oss-sec/2018/q1/38","http://www.securityfocus.com/bid/102525","http://www.securitytracker.com/id/1040162","https://access.redhat.com/errata/RHSA-2018:0805","https://security.netapp.com/advisory/ntap-20190404-0003/","https://usn.ubuntu.com/3534-1/","https://usn.ubuntu.com/3536-1/","https://www.exploit-db.com/exploits/43775/","https://www.exploit-db.com/exploits/44889/","https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000001","description":"In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1000001","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1000001","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"risk":10.025999999999998,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000001"},"relatedVulnerabilities":[{"id":"CVE-2018-1000001","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"urls":["http://seclists.org/oss-sec/2018/q1/38","http://www.securityfocus.com/bid/102525","http://www.securitytracker.com/id/1040162","https://access.redhat.com/errata/RHSA-2018:0805","https://security.netapp.com/advisory/ntap-20190404-0003/","https://usn.ubuntu.com/3534-1/","https://usn.ubuntu.com/3536-1/","https://www.exploit-db.com/exploits/43775/","https://www.exploit-db.com/exploits/44889/","https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000001","description":"In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1000001","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1000001","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"risk":10.025999999999998,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000001"},"relatedVulnerabilities":[{"id":"CVE-2018-1000001","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000001","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000001","date":"2026-10-05","epss":0.13368,"percentile":0.96313}],"urls":["http://seclists.org/oss-sec/2018/q1/38","http://www.securityfocus.com/bid/102525","http://www.securitytracker.com/id/1040162","https://access.redhat.com/errata/RHSA-2018:0805","https://security.netapp.com/advisory/ntap-20190404-0003/","https://usn.ubuntu.com/3534-1/","https://usn.ubuntu.com/3536-1/","https://www.exploit-db.com/exploits/43775/","https://www.exploit-db.com/exploits/44889/","https://www.halfdog.net/Security/2017/LibcRealpathBufferUnderflow/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000001","description":"In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37434","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-37434","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-05","epss":0.18972,"percentile":0.97228}],"risk":9.486,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37434"},"relatedVulnerabilities":[{"id":"CVE-2022-37434","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-05","epss":0.18972,"percentile":0.97228}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/37","http://seclists.org/fulldisclosure/2022/Oct/38","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/42","http://www.openwall.com/lists/oss-security/2022/08/05/2","http://www.openwall.com/lists/oss-security/2022/08/09/1","https://github.com/curl/curl/issues/9271","https://github.com/ivd38/zlib_overflow","https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063","https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d","https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1","https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764","https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/","https://security.netapp.com/advisory/ntap-20220901-0005/","https://security.netapp.com/advisory/ntap-20230427-0007/","https://support.apple.com/kb/HT213488","https://support.apple.com/kb/HT213489","https://support.apple.com/kb/HT213490","https://support.apple.com/kb/HT213491","https://support.apple.com/kb/HT213493","https://support.apple.com/kb/HT213494","https://www.debian.org/security/2022/dsa-5218","https://cert-portal.siemens.com/productcert/html/ssa-150063.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-561322.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434","description":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference)."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.28-2.1ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-6321","versionConstraint":"< 1.28-2.1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6321","fix":{"state":"fixed","versions":["1.28-2.1ubuntu0.1"],"available":[{"date":"2016-11-21","kind":"advisory","version":"1.28-2.1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6321","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-6321","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-6321","date":"2026-10-05","epss":0.15745,"percentile":0.96773}],"risk":7.8725000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6321"},"relatedVulnerabilities":[{"id":"CVE-2016-6321","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6321","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-6321","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-6321","date":"2026-10-05","epss":0.15745,"percentile":0.96773}],"urls":["http://git.savannah.gnu.org/cgit/tar.git/commit/?id=7340f67b9860ea0531c1450e5aa261c50f67165d","http://lists.gnu.org/archive/html/bug-tar/2016-10/msg00016.html","http://packetstormsecurity.com/files/139370/GNU-tar-1.29-Extract-Pathname-Bypass.html","http://seclists.org/fulldisclosure/2016/Oct/102","http://seclists.org/fulldisclosure/2016/Oct/96","http://www.debian.org/security/2016/dsa-3702","http://www.securityfocus.com/bid/93937","http://www.ubuntu.com/usn/USN-3132-1","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201611-19","https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6321","description":"Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-05","epss":0.08792,"percentile":0.95036}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-18312","versionConstraint":"< 5.22.1-9ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-18312","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.6"],"available":[{"date":"2018-12-03","kind":"advisory","version":"5.22.1-9ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-18312","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18312","date":"2026-10-05","epss":0.12093,"percentile":0.96036}],"risk":6.0465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-18312"},"relatedVulnerabilities":[{"id":"CVE-2018-18312","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-18312","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18312","date":"2026-10-05","epss":0.12093,"percentile":0.96036}],"urls":["http://www.securityfocus.com/bid/106179","http://www.securitytracker.com/id/1042181","https://access.redhat.com/errata/RHSA-2019:0001","https://access.redhat.com/errata/RHSA-2019:0010","https://bugzilla.redhat.com/show_bug.cgi?id=1646734","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/","https://metacpan.org/changes/release/SHAY/perl-5.26.3","https://metacpan.org/changes/release/SHAY/perl-5.28.1","https://rt.perl.org/Public/Bug/Display.html?id=133423","https://security.gentoo.org/glsa/201909-01","https://security.netapp.com/advisory/ntap-20190221-0003/","https://usn.ubuntu.com/3834-1/","https://www.debian.org/security/2018/dsa-4347","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18312","description":"Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-18311","versionConstraint":"< 5.22.1-9ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-18311","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.6"],"available":[{"date":"2018-12-03","kind":"advisory","version":"5.22.1-9ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-18311","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-18311","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18311","date":"2026-10-05","epss":0.11676,"percentile":0.95945}],"risk":5.838,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-18311"},"relatedVulnerabilities":[{"id":"CVE-2018-18311","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-18311","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-18311","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18311","date":"2026-10-05","epss":0.11676,"percentile":0.95945}],"urls":["http://seclists.org/fulldisclosure/2019/Mar/49","http://www.securityfocus.com/bid/106145","http://www.securitytracker.com/id/1042181","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0001","https://access.redhat.com/errata/RHSA-2019:0010","https://access.redhat.com/errata/RHSA-2019:0109","https://access.redhat.com/errata/RHSA-2019:1790","https://access.redhat.com/errata/RHSA-2019:1942","https://access.redhat.com/errata/RHSA-2019:2400","https://bugzilla.redhat.com/show_bug.cgi?id=1646730","https://github.com/Perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194be","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://lists.debian.org/debian-lts-announce/2018/11/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/","https://metacpan.org/changes/release/SHAY/perl-5.26.3","https://metacpan.org/changes/release/SHAY/perl-5.28.1","https://rt.perl.org/Ticket/Display.html?id=133204","https://seclists.org/bugtraq/2019/Mar/42","https://security.gentoo.org/glsa/201909-01","https://security.netapp.com/advisory/ntap-20190221-0003/","https://support.apple.com/kb/HT209600","https://usn.ubuntu.com/3834-1/","https://usn.ubuntu.com/3834-2/","https://www.debian.org/security/2018/dsa-4347","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18311","description":"Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations."}]},{"artifact":{"id":"09f678f8187b6d3f","cpes":["cpe:2.3:a:apt:apt:1.1.10:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/ubuntu/apt@1.1.10?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.15ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-1252","versionConstraint":"< 1.2.15ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1252","fix":{"state":"fixed","versions":["1.2.15ubuntu0.2"],"available":[{"date":"2016-12-13","kind":"advisory","version":"1.2.15ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-1252","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1252","date":"2026-10-05","epss":0.07248,"percentile":0.94163}],"risk":5.436000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1252"},"relatedVulnerabilities":[{"id":"CVE-2016-1252","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1252","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1252","date":"2026-10-05","epss":0.07248,"percentile":0.94163}],"urls":["http://packetstormsecurity.com/files/140145/apt-Repository-Signing-Bypass.html","http://www.ubuntu.com/usn/USN-3156-1","https://bugs.chromium.org/p/project-zero/issues/detail?id=1020","https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1647467","https://www.debian.org/security/2016/dsa-3733","https://www.exploit-db.com/exploits/40916/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1252","description":"The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures."}]},{"artifact":{"id":"aba0f26b4d9c7fe4","cpes":["cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*"],"name":"libapt-pkg5.0","purl":"pkg:deb/ubuntu/libapt-pkg5.0@1.1.10?arch=amd64&distro=ubuntu-16.04&upstream=apt","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg5.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapt-pkg5.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.15ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1252","versionConstraint":"< 1.2.15ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1252","fix":{"state":"fixed","versions":["1.2.15ubuntu0.2"],"available":[{"date":"2016-12-13","kind":"advisory","version":"1.2.15ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-1252","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1252","date":"2026-10-05","epss":0.07248,"percentile":0.94163}],"risk":5.436000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1252"},"relatedVulnerabilities":[{"id":"CVE-2016-1252","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1252","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1252","date":"2026-10-05","epss":0.07248,"percentile":0.94163}],"urls":["http://packetstormsecurity.com/files/140145/apt-Repository-Signing-Bypass.html","http://www.ubuntu.com/usn/USN-3156-1","https://bugs.chromium.org/p/project-zero/issues/detail?id=1020","https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1647467","https://www.debian.org/security/2016/dsa-3733","https://www.exploit-db.com/exploits/40916/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1252","description":"The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6913","versionConstraint":"< 5.22.1-9ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6913","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.3"],"available":[{"date":"2018-04-16","kind":"advisory","version":"5.22.1-9ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6913","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6913","date":"2026-10-05","epss":0.10668,"percentile":0.95684}],"risk":5.334,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6913"},"relatedVulnerabilities":[{"id":"CVE-2018-6913","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6913","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6913","date":"2026-10-05","epss":0.10668,"percentile":0.95684}],"urls":["http://www.securityfocus.com/bid/103953","http://www.securitytracker.com/id/1040681","https://lists.debian.org/debian-lts-announce/2018/04/msg00009.html","https://rt.perl.org/Public/Bug/Display.html?id=131844","https://security.gentoo.org/glsa/201909-01","https://usn.ubuntu.com/3625-1/","https://usn.ubuntu.com/3625-2/","https://www.debian.org/security/2018/dsa-4172","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6913","description":"Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-18313","versionConstraint":"< 5.22.1-9ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-18313","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.6"],"available":[{"date":"2018-12-03","kind":"advisory","version":"5.22.1-9ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-18313","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18313","date":"2026-10-05","epss":0.09524,"percentile":0.95319}],"risk":4.7620000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-18313"},"relatedVulnerabilities":[{"id":"CVE-2018-18313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-18313","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18313","date":"2026-10-05","epss":0.09524,"percentile":0.95319}],"urls":["http://seclists.org/fulldisclosure/2019/Mar/49","http://www.securitytracker.com/id/1042181","https://access.redhat.com/errata/RHSA-2019:0001","https://access.redhat.com/errata/RHSA-2019:0010","https://bugzilla.redhat.com/show_bug.cgi?id=1646738","https://github.com/Perl/perl5/commit/43b2f4ef399e2fd7240b4eeb0658686ad95f8e62","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/","https://metacpan.org/changes/release/SHAY/perl-5.26.3","https://rt.perl.org/Ticket/Display.html?id=133192","https://seclists.org/bugtraq/2019/Mar/42","https://security.gentoo.org/glsa/201909-01","https://security.netapp.com/advisory/ntap-20190221-0003/","https://support.apple.com/kb/HT209600","https://usn.ubuntu.com/3834-1/","https://usn.ubuntu.com/3834-2/","https://www.debian.org/security/2018/dsa-4347","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18313","description":"Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory."}]},{"artifact":{"id":"3ba0dcfe1758b706","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/ubuntu/libbz2-1.0@1.0.6-8?arch=amd64&distro=ubuntu-16.04&upstream=bzip2","type":"deb","version":"1.0.6-8","language":"","licenses":["bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.6-8ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-3189","versionConstraint":"< 1.0.6-8ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"bzip2","version":"1.0.6-8"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-3189","fix":{"state":"fixed","versions":["1.0.6-8ubuntu0.1"],"available":[{"date":"2019-06-26","kind":"advisory","version":"1.0.6-8ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-3189","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-3189","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-3189","date":"2026-10-05","epss":0.15562,"percentile":0.96741}],"risk":4.6686,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-3189"},"relatedVulnerabilities":[{"id":"CVE-2016-3189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-3189","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-3189","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-3189","date":"2026-10-05","epss":0.15562,"percentile":0.96741}],"urls":["http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html","http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html","http://www.openwall.com/lists/oss-security/2016/06/20/1","http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html","http://www.securityfocus.com/bid/91297","http://www.securitytracker.com/id/1036132","https://bugzilla.redhat.com/show_bug.cgi?id=1319648","https://lists.apache.org/thread.html/r19b4a70ac52093115fd71d773a7a4f579599e6275a13cfcf6252c3e3%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r1dc4c9b3bd559301bdb1557245f78b8910146efb1ee534b774c5f6af%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r481cda41fefb03e04c51484ed14421d812e5ce9e0972edff10f37260%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r4ad2ea01354e394b7fa8c78a184b7e1634d51be9bc0e9e4d7e6c9305%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r5f7ac2bd631ccb12ced65b71ff11f94e76d05b22000795e4a7b61203%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r5f80cf3ade5bb73410643e885fe6b7bf9f0222daf3533e42c7ae240c%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6e3962fc9f6a79851f70cffdec5759065969cec9c6708b964464b301%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/redf17d8ad16140733b25ca402ae825d6dfa9b85f73d9fb3fd0c75d73%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rffebcbeaace56ff1fed7916700d2f414ca1366386fb1293e99b3e31e%40%3Cjira.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html","https://seclists.org/bugtraq/2019/Aug/4","https://seclists.org/bugtraq/2019/Jul/22","https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc","https://security.gentoo.org/glsa/201708-08","https://usn.ubuntu.com/4038-1/","https://usn.ubuntu.com/4038-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-3189","description":"Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9217","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9217","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-05-24","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"risk":4.5903,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9217"},"relatedVulnerabilities":[{"id":"CVE-2017-9217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"urls":["http://www.securityfocus.com/bid/98677","https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be","https://github.com/systemd/systemd/pull/5998","https://launchpad.net/bugs/1621396","https://security.netapp.com/advisory/ntap-20241213-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9217","description":"systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9217","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9217","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-05-24","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"risk":4.5903,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9217"},"relatedVulnerabilities":[{"id":"CVE-2017-9217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"urls":["http://www.securityfocus.com/bid/98677","https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be","https://github.com/systemd/systemd/pull/5998","https://launchpad.net/bugs/1621396","https://security.netapp.com/advisory/ntap-20241213-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9217","description":"systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-9217","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9217","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-05-24","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"risk":4.5903,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9217"},"relatedVulnerabilities":[{"id":"CVE-2017-9217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"urls":["http://www.securityfocus.com/bid/98677","https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be","https://github.com/systemd/systemd/pull/5998","https://launchpad.net/bugs/1621396","https://security.netapp.com/advisory/ntap-20241213-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9217","description":"systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9217","versionConstraint":"< 229-4ubuntu19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9217","fix":{"state":"fixed","versions":["229-4ubuntu19"],"available":[{"date":"2017-05-24","kind":"advisory","version":"229-4ubuntu19"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"risk":4.5903,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9217"},"relatedVulnerabilities":[{"id":"CVE-2017-9217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9217","date":"2026-10-05","epss":0.15301,"percentile":0.96679}],"urls":["http://www.securityfocus.com/bid/98677","https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be","https://github.com/systemd/systemd/pull/5998","https://launchpad.net/bugs/1621396","https://security.netapp.com/advisory/ntap-20241213-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9217","description":"systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section."}]},{"artifact":{"id":"3453f479934eac05","cpes":["cpe:2.3:a:libprocps4:libprocps4:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"libprocps4","purl":"pkg:deb/ubuntu/libprocps4@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=procps","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libprocps4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libprocps4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1123","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1123","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1123","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1123","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1123","date":"2026-10-05","epss":0.08902,"percentile":0.95092}],"risk":4.4510000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1123"},"relatedVulnerabilities":[{"id":"CVE-2018-1123","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1123","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1123","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1123","date":"2026-10-05","epss":0.08902,"percentile":0.95092}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1123","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1123","description":"procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service)."}]},{"artifact":{"id":"b2852edfb40d7492","cpes":["cpe:2.3:a:procps:procps:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/ubuntu/procps@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1123","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1123","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1123","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1123","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1123","date":"2026-10-05","epss":0.08902,"percentile":0.95092}],"risk":4.4510000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1123"},"relatedVulnerabilities":[{"id":"CVE-2018-1123","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1123","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1123","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1123","date":"2026-10-05","epss":0.08902,"percentile":0.95092}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1123","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1123","description":"procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service)."}]},{"artifact":{"id":"2a02e042a2e2365e","cpes":["cpe:2.3:a:gnupg:gnupg:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.list"},{"path":"/var/lib/dpkg/info/gnupg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.postinst"},{"path":"/var/lib/dpkg/info/gnupg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-12020","versionConstraint":"< 1.4.20-1ubuntu3.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-12020","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.2"],"available":[{"date":"2018-06-11","kind":"advisory","version":"1.4.20-1ubuntu3.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-12020","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12020","date":"2026-10-05","epss":0.08546,"percentile":0.94912}],"risk":4.273,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-12020"},"relatedVulnerabilities":[{"id":"CVE-2018-12020","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-12020","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12020","date":"2026-10-05","epss":0.08546,"percentile":0.94912}],"urls":["http://openwall.com/lists/oss-security/2018/06/08/2","http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html","http://seclists.org/fulldisclosure/2019/Apr/38","http://www.openwall.com/lists/oss-security/2019/04/30/4","http://www.securityfocus.com/bid/104450","http://www.securitytracker.com/id/1041051","https://access.redhat.com/errata/RHSA-2018:2180","https://access.redhat.com/errata/RHSA-2018:2181","https://dev.gnupg.org/T4012","https://github.com/RUB-NDS/Johnny-You-Are-Fired","https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://lists.debian.org/debian-lts-announce/2021/12/msg00027.html","https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html","https://usn.ubuntu.com/3675-1/","https://usn.ubuntu.com/3675-2/","https://usn.ubuntu.com/3675-3/","https://usn.ubuntu.com/3964-1/","https://www.debian.org/security/2018/dsa-4222","https://www.debian.org/security/2018/dsa-4223","https://www.debian.org/security/2018/dsa-4224"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-12020","description":"mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the \"--status-fd 2\" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes."}]},{"artifact":{"id":"0418cef01c888ec2","cpes":["cpe:2.3:a:gpgv:gpgv:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gnupg","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-12020","versionConstraint":"< 1.4.20-1ubuntu3.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-12020","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.2"],"available":[{"date":"2018-06-11","kind":"advisory","version":"1.4.20-1ubuntu3.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-12020","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12020","date":"2026-10-05","epss":0.08546,"percentile":0.94912}],"risk":4.273,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-12020"},"relatedVulnerabilities":[{"id":"CVE-2018-12020","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-12020","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12020","date":"2026-10-05","epss":0.08546,"percentile":0.94912}],"urls":["http://openwall.com/lists/oss-security/2018/06/08/2","http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html","http://seclists.org/fulldisclosure/2019/Apr/38","http://www.openwall.com/lists/oss-security/2019/04/30/4","http://www.securityfocus.com/bid/104450","http://www.securitytracker.com/id/1041051","https://access.redhat.com/errata/RHSA-2018:2180","https://access.redhat.com/errata/RHSA-2018:2181","https://dev.gnupg.org/T4012","https://github.com/RUB-NDS/Johnny-You-Are-Fired","https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://lists.debian.org/debian-lts-announce/2021/12/msg00027.html","https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html","https://usn.ubuntu.com/3675-1/","https://usn.ubuntu.com/3675-2/","https://usn.ubuntu.com/3675-3/","https://usn.ubuntu.com/3964-1/","https://www.debian.org/security/2018/dsa-4222","https://www.debian.org/security/2018/dsa-4223","https://www.debian.org/security/2018/dsa-4224"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-12020","description":"mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the \"--status-fd 2\" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes."}]},{"artifact":{"id":"3ba0dcfe1758b706","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.6-8:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.6-8:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/ubuntu/libbz2-1.0@1.0.6-8?arch=amd64&distro=ubuntu-16.04&upstream=bzip2","type":"deb","version":"1.0.6-8","language":"","licenses":["bzip2-1.0.6"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.6-8ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-12900","versionConstraint":"< 1.0.6-8ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"bzip2","version":"1.0.6-8"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-12900","fix":{"state":"fixed","versions":["1.0.6-8ubuntu0.1"],"available":[{"date":"2019-06-26","kind":"advisory","version":"1.0.6-8ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-05","epss":0.07977,"percentile":0.94592}],"risk":3.9884999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-12900"},"relatedVulnerabilities":[{"id":"CVE-2019-12900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12900","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12900","date":"2026-10-05","epss":0.07977,"percentile":0.94592}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html","http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html","http://packetstormsecurity.com/files/153644/Slackware-Security-Advisory-bzip2-Updates.html","http://packetstormsecurity.com/files/153957/FreeBSD-Security-Advisory-FreeBSD-SA-19-18.bzip2.html","https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824db71a8ffee5962cdbc","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rce8cd8c30f60604b580ea01bebda8a671a25c9a1629f409fc24e7774%40%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/rda98305669476c4d90cc8527c4deda7e449019dd1fe9936b56671dd4%40%3Cuser.flink.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00021.html","https://lists.debian.org/debian-lts-announce/2019/07/msg00014.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00012.html","https://lists.debian.org/debian-lts-announce/2019/10/msg00018.html","https://seclists.org/bugtraq/2019/Aug/4","https://seclists.org/bugtraq/2019/Jul/22","https://security.FreeBSD.org/advisories/FreeBSD-SA-19:18.bzip2.asc","https://support.f5.com/csp/article/K68713584?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4038-1/","https://usn.ubuntu.com/4038-2/","https://usn.ubuntu.com/4146-1/","https://usn.ubuntu.com/4146-2/","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12900","description":"BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1049","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1049","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"risk":3.7205000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1049"},"relatedVulnerabilities":[{"id":"CVE-2018-1049","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"urls":["http://www.securitytracker.com/id/1041520","https://access.redhat.com/errata/RHSA-2018:0260","https://bugzilla.redhat.com/show_bug.cgi?id=1534701","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://usn.ubuntu.com/3558-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1049","description":"In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1049","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1049","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"risk":3.7205000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1049"},"relatedVulnerabilities":[{"id":"CVE-2018-1049","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"urls":["http://www.securitytracker.com/id/1041520","https://access.redhat.com/errata/RHSA-2018:0260","https://bugzilla.redhat.com/show_bug.cgi?id=1534701","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://usn.ubuntu.com/3558-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1049","description":"In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1049","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1049","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"risk":3.7205000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1049"},"relatedVulnerabilities":[{"id":"CVE-2018-1049","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"urls":["http://www.securitytracker.com/id/1041520","https://access.redhat.com/errata/RHSA-2018:0260","https://bugzilla.redhat.com/show_bug.cgi?id=1534701","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://usn.ubuntu.com/3558-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1049","description":"In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1049","versionConstraint":"< 229-4ubuntu21.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1049","fix":{"state":"fixed","versions":["229-4ubuntu21.1"],"available":[{"date":"2018-02-05","kind":"advisory","version":"229-4ubuntu21.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"risk":3.7205000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1049"},"relatedVulnerabilities":[{"id":"CVE-2018-1049","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1049","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1049","date":"2026-10-05","epss":0.07441,"percentile":0.94281}],"urls":["http://www.securitytracker.com/id/1041520","https://access.redhat.com/errata/RHSA-2018:0260","https://bugzilla.redhat.com/show_bug.cgi?id=1534701","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://usn.ubuntu.com/3558-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1049","description":"In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-12015","versionConstraint":"< 5.22.1-9ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-12015","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.5"],"available":[{"date":"2018-06-13","kind":"advisory","version":"5.22.1-9ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-12015","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12015","date":"2026-10-05","epss":0.0731,"percentile":0.94203}],"risk":3.655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-12015"},"relatedVulnerabilities":[{"id":"CVE-2018-12015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-12015","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-12015","date":"2026-10-05","epss":0.0731,"percentile":0.94203}],"urls":["http://seclists.org/fulldisclosure/2019/Mar/49","http://www.securityfocus.com/bid/104423","http://www.securitytracker.com/id/1041048","https://access.redhat.com/errata/RHSA-2019:2097","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900834","https://seclists.org/bugtraq/2019/Mar/42","https://security.netapp.com/advisory/ntap-20180927-0001/","https://support.apple.com/kb/HT209600","https://usn.ubuntu.com/3684-1/","https://usn.ubuntu.com/3684-2/","https://www.debian.org/security/2018/dsa-4226","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-12015","description":"In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-05","epss":0.07051,"percentile":0.94016}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10543","versionConstraint":"< 5.22.1-9ubuntu0.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-10543","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.9"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.22.1-9ubuntu0.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-05","epss":0.11334,"percentile":0.95867}],"risk":3.4002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10543"},"relatedVulnerabilities":[{"id":"CVE-2020-10543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-05","epss":0.11334,"percentile":0.95867}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10543","description":"Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6797","versionConstraint":"< 5.22.1-9ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6797","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.3"],"available":[{"date":"2018-04-16","kind":"advisory","version":"5.22.1-9ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6797","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6797","date":"2026-10-05","epss":0.06477,"percentile":0.93551}],"risk":3.2384999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6797"},"relatedVulnerabilities":[{"id":"CVE-2018-6797","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6797","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6797","date":"2026-10-05","epss":0.06477,"percentile":0.93551}],"urls":["http://www.securitytracker.com/id/1040681","http://www.securitytracker.com/id/1042004","https://access.redhat.com/errata/RHSA-2018:1192","https://rt.perl.org/Public/Bug/Display.html?id=132227","https://security.gentoo.org/glsa/201909-01","https://usn.ubuntu.com/3625-1/","https://www.debian.org/security/2018/dsa-4172","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6797","description":"An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12837","versionConstraint":"< 5.22.1-9ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12837","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.2"],"available":[{"date":"2017-11-13","kind":"advisory","version":"5.22.1-9ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-12837","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12837","date":"2026-10-05","epss":0.06207,"percentile":0.93317}],"risk":3.1035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12837"},"relatedVulnerabilities":[{"id":"CVE-2017-12837","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12837","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12837","date":"2026-10-05","epss":0.06207,"percentile":0.93317}],"urls":["http://www.debian.org/security/2017/dsa-3982","http://www.securityfocus.com/bid/100860","https://bugzilla.redhat.com/show_bug.cgi?id=1492091","https://perl5.git.perl.org/perl.git/commitdiff/96c83ed78aeea1a0496dd2b2d935869a822dc8a5","https://perl5.git.perl.org/perl.git/log/refs/tags/v5.24.3-RC1","https://perl5.git.perl.org/perl.git/log/refs/tags/v5.26.1-RC1","https://rt.perl.org/Public/Bug/Display.html?id=131582","https://security.netapp.com/advisory/ntap-20180426-0001/","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12837","description":"Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\\N{}' escape and the case-insensitive modifier."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-18314","versionConstraint":"< 5.22.1-9ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-18314","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.6"],"available":[{"date":"2018-12-03","kind":"advisory","version":"5.22.1-9ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-18314","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18314","date":"2026-10-05","epss":0.0606,"percentile":0.93176}],"risk":3.0300000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-18314"},"relatedVulnerabilities":[{"id":"CVE-2018-18314","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-18314","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-18314","date":"2026-10-05","epss":0.0606,"percentile":0.93176}],"urls":["http://www.securityfocus.com/bid/106145","http://www.securitytracker.com/id/1042181","https://access.redhat.com/errata/RHSA-2019:0001","https://access.redhat.com/errata/RHSA-2019:0010","https://bugzilla.redhat.com/show_bug.cgi?id=1646751","https://github.com/Perl/perl5/commit/19a498a461d7c81ae3507c450953d1148efecf4f","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/","https://metacpan.org/changes/release/SHAY/perl-5.26.3","https://rt.perl.org/Ticket/Display.html?id=131649","https://security.gentoo.org/glsa/201909-01","https://security.netapp.com/advisory/ntap-20190221-0003/","https://usn.ubuntu.com/3834-1/","https://www.debian.org/security/2018/dsa-4347","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18314","description":"Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12883","versionConstraint":"< 5.22.1-9ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12883","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.2"],"available":[{"date":"2017-11-13","kind":"advisory","version":"5.22.1-9ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-12883","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12883","date":"2026-10-05","epss":0.05908,"percentile":0.93017}],"risk":2.954,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12883"},"relatedVulnerabilities":[{"id":"CVE-2017-12883","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12883","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12883","date":"2026-10-05","epss":0.05908,"percentile":0.93017}],"urls":["http://mirror.cucumberlinux.com/cucumber/cucumber-1.0/source/lang-base/perl/patches/CVE-2017-12883.patch","http://www.debian.org/security/2017/dsa-3982","http://www.securityfocus.com/bid/100852","https://bugzilla.redhat.com/show_bug.cgi?id=1492093","https://perl5.git.perl.org/perl.git/commitdiff/2be4edede4ae226e2eebd4eff28cedd2041f300f#patch1","https://perl5.git.perl.org/perl.git/log/refs/tags/v5.24.3-RC1","https://perl5.git.perl.org/perl.git/log/refs/tags/v5.26.1-RC1","https://rt.perl.org/Public/Bug/Display.html?id=131598","https://security.netapp.com/advisory/ntap-20180426-0001/","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12883","description":"Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\\N{U+...}' escape."}]},{"artifact":{"id":"2a02e042a2e2365e","cpes":["cpe:2.3:a:gnupg:gnupg:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.list"},{"path":"/var/lib/dpkg/info/gnupg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.postinst"},{"path":"/var/lib/dpkg/info/gnupg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-6313","versionConstraint":"< 1.4.20-1ubuntu3.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6313","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.1"],"available":[{"date":"2016-08-18","kind":"advisory","version":"1.4.20-1ubuntu3.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"risk":2.69775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6313"},"relatedVulnerabilities":[{"id":"CVE-2016-6313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2674.html","http://www.debian.org/security/2016/dsa-3649","http://www.debian.org/security/2016/dsa-3650","http://www.securityfocus.com/bid/92527","http://www.securitytracker.com/id/1036635","http://www.ubuntu.com/usn/USN-3064-1","http://www.ubuntu.com/usn/USN-3065-1","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWS","https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html","https://security.gentoo.org/glsa/201610-04","https://security.gentoo.org/glsa/201612-01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6313","description":"The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits."}]},{"artifact":{"id":"0418cef01c888ec2","cpes":["cpe:2.3:a:gpgv:gpgv:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gnupg","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6313","versionConstraint":"< 1.4.20-1ubuntu3.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6313","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.1"],"available":[{"date":"2016-08-18","kind":"advisory","version":"1.4.20-1ubuntu3.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"risk":2.69775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6313"},"relatedVulnerabilities":[{"id":"CVE-2016-6313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2674.html","http://www.debian.org/security/2016/dsa-3649","http://www.debian.org/security/2016/dsa-3650","http://www.securityfocus.com/bid/92527","http://www.securitytracker.com/id/1036635","http://www.ubuntu.com/usn/USN-3064-1","http://www.ubuntu.com/usn/USN-3065-1","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWS","https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html","https://security.gentoo.org/glsa/201610-04","https://security.gentoo.org/glsa/201612-01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6313","description":"The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5-2ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-6313","versionConstraint":"< 1.6.5-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6313","fix":{"state":"fixed","versions":["1.6.5-2ubuntu0.2"],"available":[{"date":"2016-08-18","kind":"advisory","version":"1.6.5-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"risk":2.69775,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6313"},"relatedVulnerabilities":[{"id":"CVE-2016-6313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6313","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6313","date":"2026-10-05","epss":0.03597,"percentile":0.89103}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2674.html","http://www.debian.org/security/2016/dsa-3649","http://www.debian.org/security/2016/dsa-3650","http://www.securityfocus.com/bid/92527","http://www.securitytracker.com/id/1036635","http://www.ubuntu.com/usn/USN-3064-1","http://www.ubuntu.com/usn/USN-3065-1","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWS","https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html","https://security.gentoo.org/glsa/201610-04","https://security.gentoo.org/glsa/201612-01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6313","description":"The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits."}]},{"artifact":{"id":"c190d32df7482157","cpes":["cpe:2.3:a:gzip:gzip:1.6-4ubuntu1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.6-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6-4ubuntu1","language":"","licenses":["sha256:f9ac4a5d7a670e3891881a2cdba5fa2cd625c4d58eae4a7aa372ac00a06803bd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gzip","version":"1.6-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-05","epss":0.0507,"percentile":0.92074}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-05","epss":0.0507,"percentile":0.92074}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"309730a113abcdf8","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.1.1alpha\\+20120614-2ubuntu2:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/ubuntu/liblzma5@5.1.1alpha%2B20120614-2ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=xz-utils","type":"deb","version":"5.1.1alpha+20120614-2ubuntu2","language":"","licenses":["Autoconf","GPL-2","GPL-2+","GPL-3","LGPL-2","LGPL-2.1","LGPL-2.1+","PD","PD-debian","config-h","noderivs","permissive-fsf","permissive-nowarranty","probably-PD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblzma5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/liblzma5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"xz-utils","version":"5.1.1alpha+20120614-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-05","epss":0.0507,"percentile":0.92074}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-05","epss":0.0507,"percentile":0.92074}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6485","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6485","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"risk":2.3445,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6485"},"relatedVulnerabilities":[{"id":"CVE-2018-6485","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"urls":["http://bugs.debian.org/878159","http://www.securityfocus.com/bid/102912","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190404-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=22343","https://usn.ubuntu.com/4218-1/","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6485","description":"An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6485","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6485","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"risk":2.3445,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6485"},"relatedVulnerabilities":[{"id":"CVE-2018-6485","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"urls":["http://bugs.debian.org/878159","http://www.securityfocus.com/bid/102912","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190404-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=22343","https://usn.ubuntu.com/4218-1/","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6485","description":"An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6485","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6485","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"risk":2.3445,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6485"},"relatedVulnerabilities":[{"id":"CVE-2018-6485","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6485","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6485","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6485","date":"2026-10-05","epss":0.04689,"percentile":0.91518}],"urls":["http://bugs.debian.org/878159","http://www.securityfocus.com/bid/102912","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190404-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=22343","https://usn.ubuntu.com/4218-1/","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6485","description":"An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18269","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18269","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"risk":2.3145,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18269"},"relatedVulnerabilities":[{"id":"CVE-2017-18269","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"urls":["https://github.com/fingolfin/memmove-bug","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22644","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=cd66c0e584c6d692bc8347b5e72723d02b8a8ada","https://usn.ubuntu.com/4416-1/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18269","description":"An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18269","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18269","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"risk":2.3145,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18269"},"relatedVulnerabilities":[{"id":"CVE-2017-18269","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"urls":["https://github.com/fingolfin/memmove-bug","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22644","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=cd66c0e584c6d692bc8347b5e72723d02b8a8ada","https://usn.ubuntu.com/4416-1/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18269","description":"An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18269","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18269","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"risk":2.3145,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18269"},"relatedVulnerabilities":[{"id":"CVE-2017-18269","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18269","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18269","date":"2026-10-05","epss":0.04629,"percentile":0.91437}],"urls":["https://github.com/fingolfin/memmove-bug","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22644","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=cd66c0e584c6d692bc8347b5e72723d02b8a8ada","https://usn.ubuntu.com/4416-1/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18269","description":"An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.8.dfsg-2ubuntu4.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9841","versionConstraint":"< 1:1.2.8.dfsg-2ubuntu4.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-9841","fix":{"state":"fixed","versions":["1:1.2.8.dfsg-2ubuntu4.3"],"available":[{"date":"2020-01-22","kind":"advisory","version":"1:1.2.8.dfsg-2ubuntu4.3"}]},"cvss":[],"epss":[{"cve":"CVE-2016-9841","date":"2026-10-05","epss":0.0755,"percentile":0.94343}],"risk":2.265,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-9841"},"relatedVulnerabilities":[{"id":"CVE-2016-9841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9841","date":"2026-10-05","epss":0.0755,"percentile":0.94343}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","http://www.openwall.com/lists/oss-security/2016/12/05/21","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://www.securityfocus.com/bid/95131","http://www.securitytracker.com/id/1039427","http://www.securitytracker.com/id/1039596","https://access.redhat.com/errata/RHSA-2017:1220","https://access.redhat.com/errata/RHSA-2017:1221","https://access.redhat.com/errata/RHSA-2017:1222","https://access.redhat.com/errata/RHSA-2017:2999","https://access.redhat.com/errata/RHSA-2017:3046","https://access.redhat.com/errata/RHSA-2017:3047","https://access.redhat.com/errata/RHSA-2017:3453","https://bugzilla.redhat.com/show_bug.cgi?id=1402346","https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb","https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","https://security.gentoo.org/glsa/201701-56","https://security.gentoo.org/glsa/202007-54","https://security.netapp.com/advisory/ntap-20171019-0001/","https://support.apple.com/HT208112","https://support.apple.com/HT208113","https://support.apple.com/HT208115","https://support.apple.com/HT208144","https://usn.ubuntu.com/4246-1/","https://usn.ubuntu.com/4292-1/","https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","https://www.oracle.com/security-alerts/cpujul2020.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9841","description":"inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16865","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16865","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"risk":2.262,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16865"},"relatedVulnerabilities":[{"id":"CVE-2018-16865","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106525","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16865","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16865","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16865","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"risk":2.262,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16865"},"relatedVulnerabilities":[{"id":"CVE-2018-16865","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106525","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16865","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-16865","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16865","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"risk":2.262,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16865"},"relatedVulnerabilities":[{"id":"CVE-2018-16865","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106525","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16865","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16865","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16865","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"risk":2.262,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16865"},"relatedVulnerabilities":[{"id":"CVE-2018-16865","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16865","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16865","date":"2026-10-05","epss":0.03016,"percentile":0.86984}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106525","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16865","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6798","versionConstraint":"< 5.22.1-9ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6798","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.3"],"available":[{"date":"2018-04-16","kind":"advisory","version":"5.22.1-9ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6798","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6798","date":"2026-10-05","epss":0.0393,"percentile":0.90051}],"risk":1.965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6798"},"relatedVulnerabilities":[{"id":"CVE-2018-6798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6798","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6798","date":"2026-10-05","epss":0.0393,"percentile":0.90051}],"urls":["http://www.securitytracker.com/id/1040681","https://access.redhat.com/errata/RHSA-2018:1192","https://rt.perl.org/Public/Bug/Display.html?id=132063","https://security.gentoo.org/glsa/201909-01","https://usn.ubuntu.com/3625-1/","https://www.debian.org/security/2018/dsa-4172","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6798","description":"An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure."}]},{"artifact":{"id":"2a02e042a2e2365e","cpes":["cpe:2.3:a:gnupg:gnupg:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.list"},{"path":"/var/lib/dpkg/info/gnupg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.postinst"},{"path":"/var/lib/dpkg/info/gnupg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-7526","versionConstraint":"< 1.4.20-1ubuntu3.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-7526","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.3"],"available":[{"date":"2018-08-07","kind":"advisory","version":"1.4.20-1ubuntu3.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"risk":1.9175000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-7526"},"relatedVulnerabilities":[{"id":"CVE-2017-7526","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"urls":["http://www.securityfocus.com/bid/99338","http://www.securitytracker.com/id/1038915","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7526","https://eprint.iacr.org/2017/627","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=78130828e9a140a9de4dafadbc844dbb64cb709a","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=8725c99ffa41778f382ca97233183bcd687bb0ce","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=e6a3dc9900433bbc8ad362a595a3837318c28fa9","https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.html","https://usn.ubuntu.com/3733-1/","https://usn.ubuntu.com/3733-2/","https://www.debian.org/security/2017/dsa-3901","https://www.debian.org/security/2017/dsa-3960"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7526","description":"libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used."}]},{"artifact":{"id":"0418cef01c888ec2","cpes":["cpe:2.3:a:gpgv:gpgv:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gnupg","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.20-1ubuntu3.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7526","versionConstraint":"< 1.4.20-1ubuntu3.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-7526","fix":{"state":"fixed","versions":["1.4.20-1ubuntu3.3"],"available":[{"date":"2018-08-07","kind":"advisory","version":"1.4.20-1ubuntu3.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"risk":1.9175000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-7526"},"relatedVulnerabilities":[{"id":"CVE-2017-7526","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"urls":["http://www.securityfocus.com/bid/99338","http://www.securitytracker.com/id/1038915","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7526","https://eprint.iacr.org/2017/627","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=78130828e9a140a9de4dafadbc844dbb64cb709a","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=8725c99ffa41778f382ca97233183bcd687bb0ce","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=e6a3dc9900433bbc8ad362a595a3837318c28fa9","https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.html","https://usn.ubuntu.com/3733-1/","https://usn.ubuntu.com/3733-2/","https://www.debian.org/security/2017/dsa-3901","https://www.debian.org/security/2017/dsa-3960"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7526","description":"libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5-2ubuntu0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-7526","versionConstraint":"< 1.6.5-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-7526","fix":{"state":"fixed","versions":["1.6.5-2ubuntu0.3"],"available":[{"date":"2017-07-03","kind":"advisory","version":"1.6.5-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"risk":1.9175000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-7526"},"relatedVulnerabilities":[{"id":"CVE-2017-7526","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7526","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2017-7526","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7526","date":"2026-10-05","epss":0.03835,"percentile":0.89792}],"urls":["http://www.securityfocus.com/bid/99338","http://www.securitytracker.com/id/1038915","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7526","https://eprint.iacr.org/2017/627","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=78130828e9a140a9de4dafadbc844dbb64cb709a","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=8725c99ffa41778f382ca97233183bcd687bb0ce","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=e6a3dc9900433bbc8ad362a595a3837318c28fa9","https://lists.gnupg.org/pipermail/gnupg-announce/2017q2/000408.html","https://usn.ubuntu.com/3733-1/","https://usn.ubuntu.com/3733-2/","https://www.debian.org/security/2017/dsa-3901","https://www.debian.org/security/2017/dsa-3960"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7526","description":"libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-5180","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-5180","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"risk":1.8657,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-5180"},"relatedVulnerabilities":[{"id":"CVE-2015-5180","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"urls":["http://www.securityfocus.com/bid/99324","http://www.ubuntu.com/usn/USN-3239-1","http://www.ubuntu.com/usn/USN-3239-2","https://access.redhat.com/errata/RHSA-2018:0805","https://bugzilla.redhat.com/show_bug.cgi?id=1249603","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/attachment.cgi?id=8492","https://sourceware.org/bugzilla/show_bug.cgi?id=18784","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=fc82b0a2dfe7dbd35671c10510a8da1043d746a5","https://sourceware.org/ml/libc-alpha/2017-02/msg00079.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-5180","description":"res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash)."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-5180","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-5180","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"risk":1.8657,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-5180"},"relatedVulnerabilities":[{"id":"CVE-2015-5180","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"urls":["http://www.securityfocus.com/bid/99324","http://www.ubuntu.com/usn/USN-3239-1","http://www.ubuntu.com/usn/USN-3239-2","https://access.redhat.com/errata/RHSA-2018:0805","https://bugzilla.redhat.com/show_bug.cgi?id=1249603","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/attachment.cgi?id=8492","https://sourceware.org/bugzilla/show_bug.cgi?id=18784","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=fc82b0a2dfe7dbd35671c10510a8da1043d746a5","https://sourceware.org/ml/libc-alpha/2017-02/msg00079.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-5180","description":"res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash)."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-5180","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-5180","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"risk":1.8657,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-5180"},"relatedVulnerabilities":[{"id":"CVE-2015-5180","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-5180","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-5180","date":"2026-10-05","epss":0.06219,"percentile":0.9333}],"urls":["http://www.securityfocus.com/bid/99324","http://www.ubuntu.com/usn/USN-3239-1","http://www.ubuntu.com/usn/USN-3239-2","https://access.redhat.com/errata/RHSA-2018:0805","https://bugzilla.redhat.com/show_bug.cgi?id=1249603","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/attachment.cgi?id=8492","https://sourceware.org/bugzilla/show_bug.cgi?id=18784","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=fc82b0a2dfe7dbd35671c10510a8da1043d746a5","https://sourceware.org/ml/libc-alpha/2017-02/msg00079.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-5180","description":"res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash)."}]},{"artifact":{"id":"29738ecc088f0593","cpes":["cpe:2.3:a:bash:bash:4.3-14ubuntu1:*:*:*:*:*:*:*"],"name":"bash","purl":"pkg:deb/ubuntu/bash@4.3-14ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"4.3-14ubuntu1","language":"","licenses":["sha256:da7a8d93abf1eccdeaf326642c8ce9ed760f3a973ca46f3f69b3cf755bb81ade"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bash/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/bash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.list"},{"path":"/var/lib/dpkg/info/bash.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postinst"},{"path":"/var/lib/dpkg/info/bash.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postrm"},{"path":"/var/lib/dpkg/info/bash.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.preinst"},{"path":"/var/lib/dpkg/info/bash.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3-14ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-0634","versionConstraint":"< 4.3-14ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"bash","version":"4.3-14ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-0634","fix":{"state":"fixed","versions":["4.3-14ubuntu1.2"],"available":[{"date":"2017-05-17","kind":"advisory","version":"4.3-14ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-0634","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-0634","date":"2026-10-05","epss":0.06019,"percentile":0.93133}],"risk":1.8057,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-0634"},"relatedVulnerabilities":[{"id":"CVE-2016-0634","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-0634","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-0634","date":"2026-10-05","epss":0.06019,"percentile":0.93133}],"urls":["http://rhn.redhat.com/errata/RHSA-2017-0725.html","http://www.openwall.com/lists/oss-security/2016/09/16/12","http://www.openwall.com/lists/oss-security/2016/09/16/8","http://www.openwall.com/lists/oss-security/2016/09/18/11","http://www.openwall.com/lists/oss-security/2016/09/19/7","http://www.openwall.com/lists/oss-security/2016/09/20/1","http://www.openwall.com/lists/oss-security/2016/09/27/9","http://www.openwall.com/lists/oss-security/2016/09/29/27","http://www.openwall.com/lists/oss-security/2016/10/07/6","http://www.openwall.com/lists/oss-security/2016/10/10/3","http://www.openwall.com/lists/oss-security/2016/10/10/4","http://www.securityfocus.com/bid/92999","https://access.redhat.com/errata/RHSA-2017:1931","https://bugzilla.redhat.com/show_bug.cgi?id=1377613","https://security.gentoo.org/glsa/201612-39"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-0634","description":"The expansion of '\\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12723","versionConstraint":"< 5.22.1-9ubuntu0.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-12723","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.9"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.22.1-9ubuntu0.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-05","epss":0.05971,"percentile":0.93083}],"risk":1.7913,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12723"},"relatedVulnerabilities":[{"id":"CVE-2020-12723","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-05","epss":0.05971,"percentile":0.93083}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/Perl/perl5/issues/16947","https://github.com/Perl/perl5/issues/17743","https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12723","description":"regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-3706","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-3706","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"risk":1.7777999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-3706"},"relatedVulnerabilities":[{"id":"CVE-2016-3706","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","http://www.securityfocus.com/bid/88440","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20010","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=4ab2ab03d4351914ee53248dc5aef4a8c88ff8b9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-3706","description":"Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-3706","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-3706","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"risk":1.7777999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-3706"},"relatedVulnerabilities":[{"id":"CVE-2016-3706","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","http://www.securityfocus.com/bid/88440","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20010","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=4ab2ab03d4351914ee53248dc5aef4a8c88ff8b9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-3706","description":"Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-3706","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-3706","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"risk":1.7777999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-3706"},"relatedVulnerabilities":[{"id":"CVE-2016-3706","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-3706","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-3706","date":"2026-10-05","epss":0.05926,"percentile":0.93038}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","http://www.securityfocus.com/bid/88440","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20010","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=4ab2ab03d4351914ee53248dc5aef4a8c88ff8b9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-3706","description":"Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.8.dfsg-2ubuntu4.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9843","versionConstraint":"< 1:1.2.8.dfsg-2ubuntu4.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-9843","fix":{"state":"fixed","versions":["1:1.2.8.dfsg-2ubuntu4.3"],"available":[{"date":"2020-01-22","kind":"advisory","version":"1:1.2.8.dfsg-2ubuntu4.3"}]},"cvss":[],"epss":[{"cve":"CVE-2016-9843","date":"2026-10-05","epss":0.05766,"percentile":0.92861}],"risk":1.7298,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-9843"},"relatedVulnerabilities":[{"id":"CVE-2016-9843","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9843","date":"2026-10-05","epss":0.05766,"percentile":0.92861}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","http://www.openwall.com/lists/oss-security/2016/12/05/21","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://www.securityfocus.com/bid/95131","http://www.securitytracker.com/id/1039427","http://www.securitytracker.com/id/1041888","https://access.redhat.com/errata/RHSA-2017:1220","https://access.redhat.com/errata/RHSA-2017:1221","https://access.redhat.com/errata/RHSA-2017:1222","https://access.redhat.com/errata/RHSA-2017:2999","https://access.redhat.com/errata/RHSA-2017:3046","https://access.redhat.com/errata/RHSA-2017:3047","https://access.redhat.com/errata/RHSA-2017:3453","https://bugzilla.redhat.com/show_bug.cgi?id=1402351","https://github.com/madler/zlib/commit/d1d577490c15a0c6862473d7576352a9f18ef811","https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","https://security.gentoo.org/glsa/201701-56","https://security.gentoo.org/glsa/202007-54","https://security.netapp.com/advisory/ntap-20181018-0002/","https://support.apple.com/HT208112","https://support.apple.com/HT208113","https://support.apple.com/HT208115","https://support.apple.com/HT208144","https://usn.ubuntu.com/4246-1/","https://usn.ubuntu.com/4292-1/","https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9843","description":"The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation."}]},{"artifact":{"id":"9d0381d0e5c5e47d","cpes":["cpe:2.3:a:dpkg:dpkg:1.18.4ubuntu1:*:*:*:*:*:*:*"],"name":"dpkg","purl":"pkg:deb/ubuntu/dpkg@1.18.4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.18.4ubuntu1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+","public-domain-md5","public-domain-s-s-d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dpkg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/dpkg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.list"},{"path":"/var/lib/dpkg/info/dpkg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.postinst"},{"path":"/var/lib/dpkg/info/dpkg.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.postrm"},{"path":"/var/lib/dpkg/info/dpkg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.preinst"},{"path":"/var/lib/dpkg/info/dpkg.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dpkg.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"dpkg","version":"1.18.4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1664","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-05","epss":0.0324,"percentile":0.87871}],"risk":1.6199999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1664"},"relatedVulnerabilities":[{"id":"CVE-2022-1664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-05","epss":0.0324,"percentile":0.87871}],"urls":["https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=1f23dddc17f69c9598477098c7fb9936e15fa495","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=58814cacee39c4ce9e2cd0e3a3b9b57ad437eff5","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=7a6c03cb34d4a09f35df2f10779cbf1b70a5200b","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=faa4c92debe45412bfcf8a44f26e827800bb24be","https://lists.debian.org/debian-lts-announce/2022/05/msg00033.html","https://lists.debian.org/debian-security-announce/2022/msg00115.html","https://security.netapp.com/advisory/ntap-20221007-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1664","description":"Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1234","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1234","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"risk":1.617,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1234"},"relatedVulnerabilities":[{"id":"CVE-2016-1234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.html","http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html","http://seclists.org/fulldisclosure/2021/Sep/0","http://www.openwall.com/lists/oss-security/2016/03/07/16","http://www.securityfocus.com/bid/84204","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201702-11","https://sourceware.org/bugzilla/show_bug.cgi?id=19779","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5171f3079f2cc53e0548fc4967361f4d1ce9d7ea"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1234","description":"Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1234","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1234","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"risk":1.617,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1234"},"relatedVulnerabilities":[{"id":"CVE-2016-1234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.html","http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html","http://seclists.org/fulldisclosure/2021/Sep/0","http://www.openwall.com/lists/oss-security/2016/03/07/16","http://www.securityfocus.com/bid/84204","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201702-11","https://sourceware.org/bugzilla/show_bug.cgi?id=19779","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5171f3079f2cc53e0548fc4967361f4d1ce9d7ea"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1234","description":"Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1234","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1234","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"risk":1.617,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1234"},"relatedVulnerabilities":[{"id":"CVE-2016-1234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1234","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1234","date":"2026-10-05","epss":0.0539,"percentile":0.92437}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184626.html","http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html","http://seclists.org/fulldisclosure/2021/Sep/0","http://www.openwall.com/lists/oss-security/2016/03/07/16","http://www.securityfocus.com/bid/84204","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201702-11","https://sourceware.org/bugzilla/show_bug.cgi?id=19779","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5171f3079f2cc53e0548fc4967361f4d1ce9d7ea"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1234","description":"Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-05","epss":0.05354,"percentile":0.924}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.8.dfsg-2ubuntu4.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9842","versionConstraint":"< 1:1.2.8.dfsg-2ubuntu4.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-9842","fix":{"state":"fixed","versions":["1:1.2.8.dfsg-2ubuntu4.3"],"available":[{"date":"2020-01-22","kind":"advisory","version":"1:1.2.8.dfsg-2ubuntu4.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-9842","cwe":"CWE-1335","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-9842","date":"2026-10-05","epss":0.05204,"percentile":0.9224}],"risk":1.5612000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-9842"},"relatedVulnerabilities":[{"id":"CVE-2016-9842","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9842","cwe":"CWE-1335","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-9842","date":"2026-10-05","epss":0.05204,"percentile":0.9224}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","http://www.openwall.com/lists/oss-security/2016/12/05/21","http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://www.securityfocus.com/bid/95131","http://www.securitytracker.com/id/1039427","https://access.redhat.com/errata/RHSA-2017:1220","https://access.redhat.com/errata/RHSA-2017:1221","https://access.redhat.com/errata/RHSA-2017:1222","https://access.redhat.com/errata/RHSA-2017:2999","https://access.redhat.com/errata/RHSA-2017:3046","https://access.redhat.com/errata/RHSA-2017:3047","https://access.redhat.com/errata/RHSA-2017:3453","https://bugzilla.redhat.com/show_bug.cgi?id=1402348","https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958","https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","https://security.gentoo.org/glsa/201701-56","https://security.gentoo.org/glsa/202007-54","https://support.apple.com/HT208112","https://support.apple.com/HT208113","https://support.apple.com/HT208115","https://support.apple.com/HT208144","https://usn.ubuntu.com/4246-1/","https://usn.ubuntu.com/4292-1/","https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","https://www.oracle.com/security-alerts/cpujul2020.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9842","description":"The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers."}]},{"artifact":{"id":"e5eac761905d10ba","cpes":["cpe:2.3:a:libseccomp2:libseccomp2:2.2.3-2ubuntu3:*:*:*:*:*:*:*"],"name":"libseccomp2","purl":"pkg:deb/ubuntu/libseccomp2@2.2.3-2ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=libseccomp","type":"deb","version":"2.2.3-2ubuntu3","language":"","licenses":["sha256:739b879afbd6a2c602ed4e9be2dee2e60e1c1bfa0eb8a1acdb178f2ff8fd5e6f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libseccomp2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libseccomp2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libseccomp2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libseccomp2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libseccomp"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.1-0ubuntu0.16.04.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9893","versionConstraint":"< 2.4.1-0ubuntu0.16.04.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libseccomp","version":"2.2.3-2ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-9893","fix":{"state":"fixed","versions":["2.4.1-0ubuntu0.16.04.2"],"available":[{"date":"2019-05-30","kind":"advisory","version":"2.4.1-0ubuntu0.16.04.2"}]},"cvss":[],"epss":[{"cve":"CVE-2019-9893","date":"2026-10-05","epss":0.03041,"percentile":0.87081}],"risk":1.5205,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9893"},"relatedVulnerabilities":[{"id":"CVE-2019-9893","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9893","date":"2026-10-05","epss":0.03041,"percentile":0.87081}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00022.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00027.html","https://access.redhat.com/errata/RHSA-2019:3624","https://github.com/seccomp/libseccomp/issues/139","https://seclists.org/oss-sec/2019/q1/179","https://security.gentoo.org/glsa/201904-18","https://usn.ubuntu.com/4001-1/","https://usn.ubuntu.com/4001-2/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9893","description":"libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations."}]},{"artifact":{"id":"42899f1499942b30","cpes":["cpe:2.3:a:libpcre3:libpcre3:2\\:8.38-1ubuntu1:*:*:*:*:*:*:*"],"name":"libpcre3","purl":"pkg:deb/ubuntu/libpcre3@2%3A8.38-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=pcre3","type":"deb","version":"2:8.38-1ubuntu1","language":"","licenses":["sha256:ac9276490d2fa167442ae1aae33926514ad10c8886baa40046c5e367fccc5938"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpcre3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7186","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pcre3","version":"2:8.38-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-7186","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7186","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7186","date":"2026-10-05","epss":0.05033,"percentile":0.92021}],"risk":1.5099,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-7186"},"relatedVulnerabilities":[{"id":"CVE-2017-7186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7186","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7186","date":"2026-10-05","epss":0.05033,"percentile":0.92021}],"urls":["http://www.securityfocus.com/bid/97030","https://access.redhat.com/errata/RHSA-2018:2486","https://blogs.gentoo.org/ago/2017/03/14/libpcre-invalid-memory-read-in-match-pcre_exec-c/","https://bugs.exim.org/show_bug.cgi?id=2052","https://security.gentoo.org/glsa/201710-09","https://security.gentoo.org/glsa/201710-25","https://vcs.pcre.org/pcre/code/trunk/pcre_internal.h?r1=1649&r2=1688&sortby=date","https://vcs.pcre.org/pcre/code/trunk/pcre_ucd.c?r1=1490&r2=1688&sortby=date","https://vcs.pcre.org/pcre2/code/trunk/src/pcre2_internal.h?r1=600&r2=670&sortby=date","https://vcs.pcre.org/pcre2/code/trunk/src/pcre2_ucd.c?r1=316&r2=670&sortby=date"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7186","description":"libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10878","versionConstraint":"< 5.22.1-9ubuntu0.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-10878","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.9"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.22.1-9ubuntu0.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10878","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10878","date":"2026-10-05","epss":0.04879,"percentile":0.91802}],"risk":1.4637,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10878"},"relatedVulnerabilities":[{"id":"CVE-2020-10878","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10878","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10878","date":"2026-10-05","epss":0.04879,"percentile":0.91802}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/perl/perl5/commit/0a320d753fe7fca03df259a4dfd8e641e51edaa8","https://github.com/perl/perl5/commit/3295b48defa0f8570114877b063fe546dd348b3c","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10878","description":"Perl before 5.30.3 has an integer overflow related to mishandling of a \"PL_regkind[OP(n)] == NOTHING\" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-05","epss":0.0482,"percentile":0.91711}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.8.dfsg-2ubuntu4.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9840","versionConstraint":"< 1:1.2.8.dfsg-2ubuntu4.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-9840","fix":{"state":"fixed","versions":["1:1.2.8.dfsg-2ubuntu4.3"],"available":[{"date":"2020-01-22","kind":"advisory","version":"1:1.2.8.dfsg-2ubuntu4.3"}]},"cvss":[],"epss":[{"cve":"CVE-2016-9840","date":"2026-10-05","epss":0.04793,"percentile":0.91675}],"risk":1.4379,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-9840"},"relatedVulnerabilities":[{"id":"CVE-2016-9840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9840","date":"2026-10-05","epss":0.04793,"percentile":0.91675}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","http://www.openwall.com/lists/oss-security/2016/12/05/21","http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://www.securityfocus.com/bid/95131","http://www.securitytracker.com/id/1039427","https://access.redhat.com/errata/RHSA-2017:1220","https://access.redhat.com/errata/RHSA-2017:1221","https://access.redhat.com/errata/RHSA-2017:1222","https://access.redhat.com/errata/RHSA-2017:2999","https://access.redhat.com/errata/RHSA-2017:3046","https://access.redhat.com/errata/RHSA-2017:3047","https://access.redhat.com/errata/RHSA-2017:3453","https://bugzilla.redhat.com/show_bug.cgi?id=1402345","https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0","https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","https://security.gentoo.org/glsa/201701-56","https://security.gentoo.org/glsa/202007-54","https://support.apple.com/HT208112","https://support.apple.com/HT208113","https://support.apple.com/HT208115","https://support.apple.com/HT208144","https://usn.ubuntu.com/4246-1/","https://usn.ubuntu.com/4292-1/","https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","https://www.oracle.com/security-alerts/cpujul2020.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9840","description":"inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-05","epss":0.04731,"percentile":0.91581}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000366","versionConstraint":"< 2.23-0ubuntu9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000366","fix":{"state":"fixed","versions":["2.23-0ubuntu9"],"available":[{"date":"2017-06-19","kind":"advisory","version":"2.23-0ubuntu9"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"risk":1.3665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000366"},"relatedVulnerabilities":[{"id":"CVE-2017-1000366","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"urls":["http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html","http://seclists.org/fulldisclosure/2019/Sep/7","http://www.debian.org/security/2017/dsa-3887","http://www.securityfocus.com/bid/99127","http://www.securitytracker.com/id/1038712","https://access.redhat.com/errata/RHSA-2017:1479","https://access.redhat.com/errata/RHSA-2017:1480","https://access.redhat.com/errata/RHSA-2017:1481","https://access.redhat.com/errata/RHSA-2017:1567","https://access.redhat.com/errata/RHSA-2017:1712","https://access.redhat.com/security/cve/CVE-2017-1000366","https://kc.mcafee.com/corporate/index?page=content&id=SB10205","https://seclists.org/bugtraq/2019/Sep/7","https://security.gentoo.org/glsa/201706-19","https://www.exploit-db.com/exploits/42274/","https://www.exploit-db.com/exploits/42275/","https://www.exploit-db.com/exploits/42276/","https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt","https://www.suse.com/security/cve/CVE-2017-1000366/","https://www.suse.com/support/kb/doc/?id=7020973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000366","description":"glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000366","versionConstraint":"< 2.23-0ubuntu9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000366","fix":{"state":"fixed","versions":["2.23-0ubuntu9"],"available":[{"date":"2017-06-19","kind":"advisory","version":"2.23-0ubuntu9"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"risk":1.3665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000366"},"relatedVulnerabilities":[{"id":"CVE-2017-1000366","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"urls":["http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html","http://seclists.org/fulldisclosure/2019/Sep/7","http://www.debian.org/security/2017/dsa-3887","http://www.securityfocus.com/bid/99127","http://www.securitytracker.com/id/1038712","https://access.redhat.com/errata/RHSA-2017:1479","https://access.redhat.com/errata/RHSA-2017:1480","https://access.redhat.com/errata/RHSA-2017:1481","https://access.redhat.com/errata/RHSA-2017:1567","https://access.redhat.com/errata/RHSA-2017:1712","https://access.redhat.com/security/cve/CVE-2017-1000366","https://kc.mcafee.com/corporate/index?page=content&id=SB10205","https://seclists.org/bugtraq/2019/Sep/7","https://security.gentoo.org/glsa/201706-19","https://www.exploit-db.com/exploits/42274/","https://www.exploit-db.com/exploits/42275/","https://www.exploit-db.com/exploits/42276/","https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt","https://www.suse.com/security/cve/CVE-2017-1000366/","https://www.suse.com/support/kb/doc/?id=7020973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000366","description":"glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000366","versionConstraint":"< 2.23-0ubuntu9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000366","fix":{"state":"fixed","versions":["2.23-0ubuntu9"],"available":[{"date":"2017-06-19","kind":"advisory","version":"2.23-0ubuntu9"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"risk":1.3665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000366"},"relatedVulnerabilities":[{"id":"CVE-2017-1000366","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000366","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000366","date":"2026-10-05","epss":0.02733,"percentile":0.85611}],"urls":["http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html","http://seclists.org/fulldisclosure/2019/Sep/7","http://www.debian.org/security/2017/dsa-3887","http://www.securityfocus.com/bid/99127","http://www.securitytracker.com/id/1038712","https://access.redhat.com/errata/RHSA-2017:1479","https://access.redhat.com/errata/RHSA-2017:1480","https://access.redhat.com/errata/RHSA-2017:1481","https://access.redhat.com/errata/RHSA-2017:1567","https://access.redhat.com/errata/RHSA-2017:1712","https://access.redhat.com/security/cve/CVE-2017-1000366","https://kc.mcafee.com/corporate/index?page=content&id=SB10205","https://seclists.org/bugtraq/2019/Sep/7","https://security.gentoo.org/glsa/201706-19","https://www.exploit-db.com/exploits/42274/","https://www.exploit-db.com/exploits/42275/","https://www.exploit-db.com/exploits/42276/","https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt","https://www.suse.com/security/cve/CVE-2017-1000366/","https://www.suse.com/support/kb/doc/?id=7020973"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000366","description":"glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier."}]},{"artifact":{"id":"42899f1499942b30","cpes":["cpe:2.3:a:libpcre3:libpcre3:2\\:8.38-1ubuntu1:*:*:*:*:*:*:*"],"name":"libpcre3","purl":"pkg:deb/ubuntu/libpcre3@2%3A8.38-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=pcre3","type":"deb","version":"2:8.38-1ubuntu1","language":"","licenses":["sha256:ac9276490d2fa167442ae1aae33926514ad10c8886baa40046c5e367fccc5938"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpcre3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-6004","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pcre3","version":"2:8.38-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-6004","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-6004","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6004","date":"2026-10-05","epss":0.04546,"percentile":0.91298}],"risk":1.3638,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-6004"},"relatedVulnerabilities":[{"id":"CVE-2017-6004","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-6004","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6004","date":"2026-10-05","epss":0.04546,"percentile":0.91298}],"urls":["http://www.securityfocus.com/bid/96295","http://www.securitytracker.com/id/1037850","https://access.redhat.com/errata/RHSA-2018:2486","https://bugs.exim.org/show_bug.cgi?id=2035","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201706-11","https://vcs.pcre.org/pcre/code/trunk/pcre_jit_compile.c?r1=1676&r2=1680&view=patch"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-6004","description":"The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-4429","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-4429","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"risk":1.3628999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-4429"},"relatedVulnerabilities":[{"id":"CVE-2016-4429","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","https://lists.debian.org/debian-lts-announce/2020/06/msg00027.html","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20112","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=bc779a1a5b3035133024b21e2f339fe4219fb11c","https://usn.ubuntu.com/3759-1/","https://usn.ubuntu.com/3759-2/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-4429","description":"Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-4429","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-4429","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"risk":1.3628999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-4429"},"relatedVulnerabilities":[{"id":"CVE-2016-4429","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","https://lists.debian.org/debian-lts-announce/2020/06/msg00027.html","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20112","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=bc779a1a5b3035133024b21e2f339fe4219fb11c","https://usn.ubuntu.com/3759-1/","https://usn.ubuntu.com/3759-2/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-4429","description":"Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-4429","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-4429","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"risk":1.3628999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-4429"},"relatedVulnerabilities":[{"id":"CVE-2016-4429","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-4429","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4429","date":"2026-10-05","epss":0.04543,"percentile":0.91282}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html","http://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.securityfocus.com/bid/102073","https://lists.debian.org/debian-lts-announce/2020/06/msg00027.html","https://source.android.com/security/bulletin/2017-12-01","https://sourceware.org/bugzilla/show_bug.cgi?id=20112","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=bc779a1a5b3035133024b21e2f339fe4219fb11c","https://usn.ubuntu.com/3759-1/","https://usn.ubuntu.com/3759-2/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-4429","description":"Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-05","epss":0.04293,"percentile":0.90832}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000082","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000082","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"risk":1.1634,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000082"},"relatedVulnerabilities":[{"id":"CVE-2017-1000082","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"urls":["http://www.openwall.com/lists/oss-security/2017/07/02/1","http://www.securityfocus.com/bid/99507","http://www.securitytracker.com/id/1038839","https://github.com/systemd/systemd/issues/6237"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000082","description":"systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. \"0day\"), running the service in question with root privileges rather than the user intended."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000082","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000082","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"risk":1.1634,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000082"},"relatedVulnerabilities":[{"id":"CVE-2017-1000082","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"urls":["http://www.openwall.com/lists/oss-security/2017/07/02/1","http://www.securityfocus.com/bid/99507","http://www.securitytracker.com/id/1038839","https://github.com/systemd/systemd/issues/6237"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000082","description":"systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. \"0day\"), running the service in question with root privileges rather than the user intended."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-1000082","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000082","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"risk":1.1634,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000082"},"relatedVulnerabilities":[{"id":"CVE-2017-1000082","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"urls":["http://www.openwall.com/lists/oss-security/2017/07/02/1","http://www.securityfocus.com/bid/99507","http://www.securitytracker.com/id/1038839","https://github.com/systemd/systemd/issues/6237"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000082","description":"systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. \"0day\"), running the service in question with root privileges rather than the user intended."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000082","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000082","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"risk":1.1634,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000082"},"relatedVulnerabilities":[{"id":"CVE-2017-1000082","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000082","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000082","date":"2026-10-05","epss":0.03878,"percentile":0.89904}],"urls":["http://www.openwall.com/lists/oss-security/2017/07/02/1","http://www.securityfocus.com/bid/99507","http://www.securitytracker.com/id/1038839","https://github.com/systemd/systemd/issues/6237"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000082","description":"systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. \"0day\"), running the service in question with root privileges rather than the user intended."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6323","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6323","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"risk":1.1523,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6323"},"relatedVulnerabilities":[{"id":"CVE-2016-6323","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-10/msg00009.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.openwall.com/lists/oss-security/2016/08/18/12","http://www.securityfocus.com/bid/92532","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KTXSOVCRDGBIB4WCIDAGYYUBESXZ4IGK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVWSAZVBTLALXF4SCBPDV3FY6J22DXLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WO7IMEYWZ2WTXGGMZBWWSDCUMFN63XOB/","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/show_bug.cgi?id=20435","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=9e2ff6c9cc54c0b4402b8d49e4abe7000fde7617"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6323","description":"The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6323","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6323","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"risk":1.1523,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6323"},"relatedVulnerabilities":[{"id":"CVE-2016-6323","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-10/msg00009.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.openwall.com/lists/oss-security/2016/08/18/12","http://www.securityfocus.com/bid/92532","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KTXSOVCRDGBIB4WCIDAGYYUBESXZ4IGK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVWSAZVBTLALXF4SCBPDV3FY6J22DXLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WO7IMEYWZ2WTXGGMZBWWSDCUMFN63XOB/","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/show_bug.cgi?id=20435","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=9e2ff6c9cc54c0b4402b8d49e4abe7000fde7617"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6323","description":"The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6323","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6323","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"risk":1.1523,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6323"},"relatedVulnerabilities":[{"id":"CVE-2016-6323","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6323","cwe":"CWE-284","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6323","date":"2026-10-05","epss":0.03841,"percentile":0.8981}],"urls":["http://lists.opensuse.org/opensuse-updates/2016-10/msg00009.html","http://www-01.ibm.com/support/docview.wss?uid=swg21995039","http://www.openwall.com/lists/oss-security/2016/08/18/12","http://www.securityfocus.com/bid/92532","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KTXSOVCRDGBIB4WCIDAGYYUBESXZ4IGK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVWSAZVBTLALXF4SCBPDV3FY6J22DXLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WO7IMEYWZ2WTXGGMZBWWSDCUMFN63XOB/","https://security.gentoo.org/glsa/201706-19","https://sourceware.org/bugzilla/show_bug.cgi?id=20435","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=9e2ff6c9cc54c0b4402b8d49e4abe7000fde7617"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6323","description":"The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15686","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15686","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"risk":1.1305,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15686"},"relatedVulnerabilities":[{"id":"CVE-2018-15686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"urls":["http://www.securityfocus.com/bid/105747","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://github.com/systemd/systemd/pull/10519","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45714/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15686","description":"A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15686","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15686","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"risk":1.1305,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15686"},"relatedVulnerabilities":[{"id":"CVE-2018-15686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"urls":["http://www.securityfocus.com/bid/105747","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://github.com/systemd/systemd/pull/10519","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45714/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15686","description":"A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-15686","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15686","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"risk":1.1305,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15686"},"relatedVulnerabilities":[{"id":"CVE-2018-15686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"urls":["http://www.securityfocus.com/bid/105747","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://github.com/systemd/systemd/pull/10519","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45714/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15686","description":"A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15686","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15686","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"risk":1.1305,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15686"},"relatedVulnerabilities":[{"id":"CVE-2018-15686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15686","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15686","date":"2026-10-05","epss":0.02261,"percentile":0.82392}],"urls":["http://www.securityfocus.com/bid/105747","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://github.com/systemd/systemd/pull/10519","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45714/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15686","description":"A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"8922671e543fd89c","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux%402.27.1-1ubuntu3","type":"deb","version":"1:2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.27.1-1ubuntu3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"3d1b10a30b1b1cdd","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"4f96f62ec4d3c8d6","cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"libfdisk1","purl":"pkg:deb/ubuntu/libfdisk1@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"95ceaf8f813b2969","cpes":["cpe:2.3:a:libmount1:libmount1:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"1670d0bcfc782f37","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"6c5a5bea5e2d2201","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"74437920f9fb1946","cpes":["cpe:2.3:a:mount:mount:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=util-linux","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"d22816271ea2e55a","cpes":["cpe:2.3:a:util-linux:util-linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.27.1-1ubuntu3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.27.1-1ubuntu3?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2.27.1-1ubuntu3","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.preinst"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-28085","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"util-linux","version":"2.27.1-1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-28085","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"risk":1.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28085"},"relatedVulnerabilities":[{"id":"CVE-2024-28085","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28085","cwe":"CWE-150","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28085","date":"2026-10-05","epss":0.02242,"percentile":0.82266}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/27/5","http://www.openwall.com/lists/oss-security/2024/03/27/6","http://www.openwall.com/lists/oss-security/2024/03/27/7","http://www.openwall.com/lists/oss-security/2024/03/27/8","http://www.openwall.com/lists/oss-security/2024/03/27/9","http://www.openwall.com/lists/oss-security/2024/03/28/1","http://www.openwall.com/lists/oss-security/2024/03/28/2","http://www.openwall.com/lists/oss-security/2024/03/28/3","https://github.com/skyler-ferrante/CVE-2024-28085","https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq","https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html","https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/","https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt","https://security.netapp.com/advisory/ntap-20240531-0003/","https://www.openwall.com/lists/oss-security/2024/03/27/5","http://seclists.org/fulldisclosure/2024/Mar/35","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://github.com/util-linux/util-linux/discussions/2868"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085","description":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover."}]},{"artifact":{"id":"dd71cd9f5366f495","cpes":["cpe:2.3:a:sensible-utils:sensible-utils:0.0.9:*:*:*:*:*:*:*","cpe:2.3:a:sensible-utils:sensible_utils:0.0.9:*:*:*:*:*:*:*","cpe:2.3:a:sensible_utils:sensible-utils:0.0.9:*:*:*:*:*:*:*","cpe:2.3:a:sensible_utils:sensible_utils:0.0.9:*:*:*:*:*:*:*","cpe:2.3:a:sensible:sensible-utils:0.0.9:*:*:*:*:*:*:*","cpe:2.3:a:sensible:sensible_utils:0.0.9:*:*:*:*:*:*:*"],"name":"sensible-utils","purl":"pkg:deb/ubuntu/sensible-utils@0.0.9?arch=all&distro=ubuntu-16.04","type":"deb","version":"0.0.9","language":"","licenses":["sha256:5c58dcf1d8debb43fcec08ae0cbf2f049aa5d48c567147046db48e42c2f706ac"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sensible-utils/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/sensible-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sensible-utils.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/sensible-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sensible-utils.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/sensible-utils.list"},{"path":"/var/lib/dpkg/info/sensible-utils.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/sensible-utils.postinst"},{"path":"/var/lib/dpkg/info/sensible-utils.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/sensible-utils.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.0.9ubuntu0.16.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-17512","versionConstraint":"< 0.0.9ubuntu0.16.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"sensible-utils","version":"0.0.9"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-17512","fix":{"state":"fixed","versions":["0.0.9ubuntu0.16.04.1"],"available":[{"date":"2018-02-26","kind":"advisory","version":"0.0.9ubuntu0.16.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-17512","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17512","date":"2026-10-05","epss":0.02235,"percentile":0.82203}],"risk":1.1175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-17512"},"relatedVulnerabilities":[{"id":"CVE-2017-17512","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17512","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17512","date":"2026-10-05","epss":0.02235,"percentile":0.82203}],"urls":["http://metadata.ftp-master.debian.org/changelogs/main/s/sensible-utils/sensible-utils_0.0.11_changelog","https://bugs.debian.org/881767","https://lists.debian.org/debian-lts-announce/2017/12/msg00012.html","https://usn.ubuntu.com/3584-1/","https://www.debian.org/security/2017/dsa-4071"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17512","description":"sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"risk":1.117,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-19189"},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"risk":1.117,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-19189"},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"risk":1.117,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-19189"},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"risk":1.117,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-19189"},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"risk":1.117,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-19189"},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-05","epss":0.02234,"percentile":0.82188}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-25013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-25013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"risk":1.0695,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-25013"},"relatedVulnerabilities":[{"id":"CVE-2019-25013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"urls":["https://lists.apache.org/thread.html/r32d767ac804e9b8aad4355bb85960a6a1385eab7afff549a5e98660f%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r448bb851cc8e6e3f93f3c28c70032b37062625d81214744474ac49e7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r4806a391091e082bdea17266452ca656ebc176e51bb3932733b3a0a2%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r499e4f96d0b5109ef083f2feccd33c51650c1b7d7068aa3bd47efca9%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r5af4430421bb6f9973294691a7904bbd260937e9eef96b20556f43ff%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r750eee18542bc02bd8350861c424ee60a9b9b225568fa09436a37ece%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a2e94adfe0a2f0a1d42e4927e8c32ecac97d37db9cb68095fe9ddbc%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd2354f9ccce41e494fbadcbc5ad87218de6ec0fff8a7b54c8462226c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4Y6TX47P47KABSFOL26FLDNVCWXDKDEZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVCUNLQ3HXGS4VPUQKWTJGRAW2KTFGXS/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210205-0004/","https://sourceware.org/bugzilla/show_bug.cgi?id=24973","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ee7a3144c9922808181009b7b3e50e852fb4999b","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-25013","description":"The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-25013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-25013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"risk":1.0695,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-25013"},"relatedVulnerabilities":[{"id":"CVE-2019-25013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"urls":["https://lists.apache.org/thread.html/r32d767ac804e9b8aad4355bb85960a6a1385eab7afff549a5e98660f%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r448bb851cc8e6e3f93f3c28c70032b37062625d81214744474ac49e7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r4806a391091e082bdea17266452ca656ebc176e51bb3932733b3a0a2%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r499e4f96d0b5109ef083f2feccd33c51650c1b7d7068aa3bd47efca9%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r5af4430421bb6f9973294691a7904bbd260937e9eef96b20556f43ff%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r750eee18542bc02bd8350861c424ee60a9b9b225568fa09436a37ece%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a2e94adfe0a2f0a1d42e4927e8c32ecac97d37db9cb68095fe9ddbc%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd2354f9ccce41e494fbadcbc5ad87218de6ec0fff8a7b54c8462226c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4Y6TX47P47KABSFOL26FLDNVCWXDKDEZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVCUNLQ3HXGS4VPUQKWTJGRAW2KTFGXS/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210205-0004/","https://sourceware.org/bugzilla/show_bug.cgi?id=24973","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ee7a3144c9922808181009b7b3e50e852fb4999b","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-25013","description":"The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-25013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-25013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"risk":1.0695,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-25013"},"relatedVulnerabilities":[{"id":"CVE-2019-25013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-25013","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-25013","date":"2026-10-05","epss":0.03565,"percentile":0.8899}],"urls":["https://lists.apache.org/thread.html/r32d767ac804e9b8aad4355bb85960a6a1385eab7afff549a5e98660f%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r448bb851cc8e6e3f93f3c28c70032b37062625d81214744474ac49e7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r4806a391091e082bdea17266452ca656ebc176e51bb3932733b3a0a2%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r499e4f96d0b5109ef083f2feccd33c51650c1b7d7068aa3bd47efca9%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r5af4430421bb6f9973294691a7904bbd260937e9eef96b20556f43ff%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r750eee18542bc02bd8350861c424ee60a9b9b225568fa09436a37ece%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a2e94adfe0a2f0a1d42e4927e8c32ecac97d37db9cb68095fe9ddbc%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd2354f9ccce41e494fbadcbc5ad87218de6ec0fff8a7b54c8462226c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4Y6TX47P47KABSFOL26FLDNVCWXDKDEZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVCUNLQ3HXGS4VPUQKWTJGRAW2KTFGXS/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210205-0004/","https://sourceware.org/bugzilla/show_bug.cgi?id=24973","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ee7a3144c9922808181009b7b3e50e852fb4999b","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-25013","description":"The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6454","versionConstraint":"< 229-4ubuntu21.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-6454","fix":{"state":"fixed","versions":["229-4ubuntu21.16"],"available":[{"date":"2019-02-18","kind":"advisory","version":"229-4ubuntu21.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"risk":1.0175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6454"},"relatedVulnerabilities":[{"id":"CVE-2019-6454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://www.openwall.com/lists/oss-security/2019/02/18/3","http://www.openwall.com/lists/oss-security/2019/02/19/1","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/107081","https://access.redhat.com/errata/RHSA-2019:0368","https://access.redhat.com/errata/RHSA-2019:0990","https://access.redhat.com/errata/RHSA-2019:1322","https://access.redhat.com/errata/RHSA-2019:1502","https://access.redhat.com/errata/RHSA-2019:2805","https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://lists.debian.org/debian-lts-announce/2019/02/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/","https://security.netapp.com/advisory/ntap-20190327-0004/","https://usn.ubuntu.com/3891-1/","https://www.debian.org/security/2019/dsa-4393"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6454","description":"An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic)."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6454","versionConstraint":"< 229-4ubuntu21.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-6454","fix":{"state":"fixed","versions":["229-4ubuntu21.16"],"available":[{"date":"2019-02-18","kind":"advisory","version":"229-4ubuntu21.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"risk":1.0175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6454"},"relatedVulnerabilities":[{"id":"CVE-2019-6454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://www.openwall.com/lists/oss-security/2019/02/18/3","http://www.openwall.com/lists/oss-security/2019/02/19/1","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/107081","https://access.redhat.com/errata/RHSA-2019:0368","https://access.redhat.com/errata/RHSA-2019:0990","https://access.redhat.com/errata/RHSA-2019:1322","https://access.redhat.com/errata/RHSA-2019:1502","https://access.redhat.com/errata/RHSA-2019:2805","https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://lists.debian.org/debian-lts-announce/2019/02/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/","https://security.netapp.com/advisory/ntap-20190327-0004/","https://usn.ubuntu.com/3891-1/","https://www.debian.org/security/2019/dsa-4393"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6454","description":"An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic)."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-6454","versionConstraint":"< 229-4ubuntu21.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-6454","fix":{"state":"fixed","versions":["229-4ubuntu21.16"],"available":[{"date":"2019-02-18","kind":"advisory","version":"229-4ubuntu21.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"risk":1.0175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6454"},"relatedVulnerabilities":[{"id":"CVE-2019-6454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://www.openwall.com/lists/oss-security/2019/02/18/3","http://www.openwall.com/lists/oss-security/2019/02/19/1","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/107081","https://access.redhat.com/errata/RHSA-2019:0368","https://access.redhat.com/errata/RHSA-2019:0990","https://access.redhat.com/errata/RHSA-2019:1322","https://access.redhat.com/errata/RHSA-2019:1502","https://access.redhat.com/errata/RHSA-2019:2805","https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://lists.debian.org/debian-lts-announce/2019/02/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/","https://security.netapp.com/advisory/ntap-20190327-0004/","https://usn.ubuntu.com/3891-1/","https://www.debian.org/security/2019/dsa-4393"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6454","description":"An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic)."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6454","versionConstraint":"< 229-4ubuntu21.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-6454","fix":{"state":"fixed","versions":["229-4ubuntu21.16"],"available":[{"date":"2019-02-18","kind":"advisory","version":"229-4ubuntu21.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"risk":1.0175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6454"},"relatedVulnerabilities":[{"id":"CVE-2019-6454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6454","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6454","date":"2026-10-05","epss":0.02035,"percentile":0.80407}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html","http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://www.openwall.com/lists/oss-security/2019/02/18/3","http://www.openwall.com/lists/oss-security/2019/02/19/1","http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/107081","https://access.redhat.com/errata/RHSA-2019:0368","https://access.redhat.com/errata/RHSA-2019:0990","https://access.redhat.com/errata/RHSA-2019:1322","https://access.redhat.com/errata/RHSA-2019:1502","https://access.redhat.com/errata/RHSA-2019:2805","https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://lists.debian.org/debian-lts-announce/2019/02/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/","https://security.netapp.com/advisory/ntap-20190327-0004/","https://usn.ubuntu.com/3891-1/","https://www.debian.org/security/2019/dsa-4393"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6454","description":"An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic)."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-5417","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-5417","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"risk":1.0083,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-5417"},"relatedVulnerabilities":[{"id":"CVE-2016-5417","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"urls":["http://www.openwall.com/lists/oss-security/2016/08/02/5","http://www.securityfocus.com/bid/92257","https://sourceware.org/bugzilla/show_bug.cgi?id=19257","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7","https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-5417","description":"Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-5417","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-5417","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"risk":1.0083,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-5417"},"relatedVulnerabilities":[{"id":"CVE-2016-5417","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"urls":["http://www.openwall.com/lists/oss-security/2016/08/02/5","http://www.securityfocus.com/bid/92257","https://sourceware.org/bugzilla/show_bug.cgi?id=19257","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7","https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-5417","description":"Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-5417","versionConstraint":"< 2.23-0ubuntu6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-5417","fix":{"state":"fixed","versions":["2.23-0ubuntu6"],"available":[{"date":"2017-03-21","kind":"advisory","version":"2.23-0ubuntu6"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"risk":1.0083,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-5417"},"relatedVulnerabilities":[{"id":"CVE-2016-5417","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-5417","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-5417","date":"2026-10-05","epss":0.03361,"percentile":0.88345}],"urls":["http://www.openwall.com/lists/oss-security/2016/08/02/5","http://www.securityfocus.com/bid/92257","https://sourceware.org/bugzilla/show_bug.cgi?id=19257","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=2212c1420c92a33b0e0bd9a34938c9814a56c0f7","https://www.sourceware.org/ml/libc-alpha/2016-08/msg00212.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-5417","description":"Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"risk":0.9669000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010022"},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"risk":0.9669000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010022"},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"risk":0.9669000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010022"},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-05","epss":0.03223,"percentile":0.87816}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"risk":0.9578999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010024"},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"risk":0.9578999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010024"},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"risk":0.9578999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010024"},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-05","epss":0.03193,"percentile":0.87685}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3453f479934eac05","cpes":["cpe:2.3:a:libprocps4:libprocps4:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"libprocps4","purl":"pkg:deb/ubuntu/libprocps4@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=procps","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libprocps4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libprocps4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1124","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1124","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1124","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1124","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1124","date":"2026-10-05","epss":0.01901,"percentile":0.78979}],"risk":0.9504999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1124"},"relatedVulnerabilities":[{"id":"CVE-2018-1124","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1124","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1124","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1124","date":"2026-10-05","epss":0.01901,"percentile":0.78979}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","http://www.securitytracker.com/id/1041057","https://access.redhat.com/errata/RHSA-2018:1700","https://access.redhat.com/errata/RHSA-2018:1777","https://access.redhat.com/errata/RHSA-2018:1820","https://access.redhat.com/errata/RHSA-2018:2267","https://access.redhat.com/errata/RHSA-2018:2268","https://access.redhat.com/errata/RHSA-2019:1944","https://access.redhat.com/errata/RHSA-2019:2401","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1124","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://kc.mcafee.com/corporate/index?page=content&id=SB10241","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-2/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1124","description":"procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users."}]},{"artifact":{"id":"b2852edfb40d7492","cpes":["cpe:2.3:a:procps:procps:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/ubuntu/procps@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1124","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1124","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1124","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1124","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1124","date":"2026-10-05","epss":0.01901,"percentile":0.78979}],"risk":0.9504999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1124"},"relatedVulnerabilities":[{"id":"CVE-2018-1124","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1124","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1124","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1124","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1124","date":"2026-10-05","epss":0.01901,"percentile":0.78979}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","http://www.securitytracker.com/id/1041057","https://access.redhat.com/errata/RHSA-2018:1700","https://access.redhat.com/errata/RHSA-2018:1777","https://access.redhat.com/errata/RHSA-2018:1820","https://access.redhat.com/errata/RHSA-2018:2267","https://access.redhat.com/errata/RHSA-2018:2268","https://access.redhat.com/errata/RHSA-2019:1944","https://access.redhat.com/errata/RHSA-2019:2401","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1124","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://kc.mcafee.com/corporate/index?page=content&id=SB10241","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-2/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1124","description":"procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users."}]},{"artifact":{"id":"3453f479934eac05","cpes":["cpe:2.3:a:libprocps4:libprocps4:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"libprocps4","purl":"pkg:deb/ubuntu/libprocps4@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=procps","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libprocps4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libprocps4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1126","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1126","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1126","date":"2026-10-05","epss":0.01876,"percentile":0.7869}],"risk":0.938,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1126"},"relatedVulnerabilities":[{"id":"CVE-2018-1126","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1126","date":"2026-10-05","epss":0.01876,"percentile":0.7869}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","http://www.securitytracker.com/id/1041057","https://access.redhat.com/errata/RHSA-2018:1700","https://access.redhat.com/errata/RHSA-2018:1777","https://access.redhat.com/errata/RHSA-2018:1820","https://access.redhat.com/errata/RHSA-2018:2267","https://access.redhat.com/errata/RHSA-2018:2268","https://access.redhat.com/errata/RHSA-2019:1944","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1126","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-2/","https://www.debian.org/security/2018/dsa-4208","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1126","description":"procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124."}]},{"artifact":{"id":"b2852edfb40d7492","cpes":["cpe:2.3:a:procps:procps:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/ubuntu/procps@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1126","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1126","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1126","date":"2026-10-05","epss":0.01876,"percentile":0.7869}],"risk":0.938,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1126"},"relatedVulnerabilities":[{"id":"CVE-2018-1126","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1126","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1126","date":"2026-10-05","epss":0.01876,"percentile":0.7869}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","http://www.securitytracker.com/id/1041057","https://access.redhat.com/errata/RHSA-2018:1700","https://access.redhat.com/errata/RHSA-2018:1777","https://access.redhat.com/errata/RHSA-2018:1820","https://access.redhat.com/errata/RHSA-2018:2267","https://access.redhat.com/errata/RHSA-2018:2268","https://access.redhat.com/errata/RHSA-2019:1944","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1126","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-2/","https://www.debian.org/security/2018/dsa-4208","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1126","description":"procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124."}]},{"artifact":{"id":"3453f479934eac05","cpes":["cpe:2.3:a:libprocps4:libprocps4:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"libprocps4","purl":"pkg:deb/ubuntu/libprocps4@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=procps","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libprocps4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libprocps4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1125","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1125","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1125","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-1125","date":"2026-10-05","epss":0.01856,"percentile":0.78456}],"risk":0.928,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1125"},"relatedVulnerabilities":[{"id":"CVE-2018-1125","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1125","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-1125","date":"2026-10-05","epss":0.01856,"percentile":0.78456}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1125","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1125","description":"procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash."}]},{"artifact":{"id":"b2852edfb40d7492","cpes":["cpe:2.3:a:procps:procps:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/ubuntu/procps@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1125","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1125","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1125","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-1125","date":"2026-10-05","epss":0.01856,"percentile":0.78456}],"risk":0.928,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1125"},"relatedVulnerabilities":[{"id":"CVE-2018-1125","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1125","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2018-1125","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-1125","date":"2026-10-05","epss":0.01856,"percentile":0.78456}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1125","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1125","description":"procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3326","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3326","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"risk":0.9279,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3326"},"relatedVulnerabilities":[{"id":"CVE-2021-3326","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"urls":["http://www.openwall.com/lists/oss-security/2021/01/28/2","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210304-0007/","https://sourceware.org/bugzilla/show_bug.cgi?id=27256","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=7d88c6142c6efc160c0ee5e4f85cde382c072888","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3326","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3326","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3326","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"risk":0.9279,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3326"},"relatedVulnerabilities":[{"id":"CVE-2021-3326","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"urls":["http://www.openwall.com/lists/oss-security/2021/01/28/2","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210304-0007/","https://sourceware.org/bugzilla/show_bug.cgi?id=27256","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=7d88c6142c6efc160c0ee5e4f85cde382c072888","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3326","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3326","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3326","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"risk":0.9279,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3326"},"relatedVulnerabilities":[{"id":"CVE-2021-3326","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3326","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3326","date":"2026-10-05","epss":0.03093,"percentile":0.87296}],"urls":["http://www.openwall.com/lists/oss-security/2021/01/28/2","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210304-0007/","https://sourceware.org/bugzilla/show_bug.cgi?id=27256","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=7d88c6142c6efc160c0ee5e4f85cde382c072888","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3326","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"risk":0.9131999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010023"},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"risk":0.9131999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010023"},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"risk":0.9131999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1010023"},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-05","epss":0.03044,"percentile":0.87091}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.28-2.1ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9923","versionConstraint":"< 1.28-2.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-9923","fix":{"state":"fixed","versions":["1.28-2.1ubuntu0.2"],"available":[{"date":"2021-01-13","kind":"advisory","version":"1.28-2.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9923","date":"2026-10-05","epss":0.03028,"percentile":0.87037}],"risk":0.9084,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9923"},"relatedVulnerabilities":[{"id":"CVE-2019-9923","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9923","date":"2026-10-05","epss":0.03028,"percentile":0.87037}],"urls":["http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html","http://savannah.gnu.org/bugs/?55369","https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9923","description":"pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15670","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15670","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"risk":0.8931,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15670"},"relatedVulnerabilities":[{"id":"CVE-2017-15670","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"urls":["http://www.securityfocus.com/bid/101521","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22320"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15670","description":"The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15670","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15670","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"risk":0.8931,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15670"},"relatedVulnerabilities":[{"id":"CVE-2017-15670","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"urls":["http://www.securityfocus.com/bid/101521","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22320"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15670","description":"The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15670","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15670","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"risk":0.8931,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15670"},"relatedVulnerabilities":[{"id":"CVE-2017-15670","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15670","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15670","date":"2026-10-05","epss":0.02977,"percentile":0.86814}],"urls":["http://www.securityfocus.com/bid/101521","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22320"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15670","description":"The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-31486","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-05","epss":0.01742,"percentile":0.76966}],"risk":0.8710000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-31486"},"relatedVulnerabilities":[{"id":"CVE-2023-31486","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-05","epss":0.01742,"percentile":0.76966}],"urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16997","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-16997","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"risk":0.8685,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-16997"},"relatedVulnerabilities":[{"id":"CVE-2017-16997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"urls":["http://www.securityfocus.com/bid/102228","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://bugs.debian.org/884615","https://sourceware.org/bugzilla/show_bug.cgi?id=22625","https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16997","description":"elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the \"./\" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16997","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-16997","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"risk":0.8685,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-16997"},"relatedVulnerabilities":[{"id":"CVE-2017-16997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"urls":["http://www.securityfocus.com/bid/102228","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://bugs.debian.org/884615","https://sourceware.org/bugzilla/show_bug.cgi?id=22625","https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16997","description":"elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the \"./\" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16997","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-16997","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"risk":0.8685,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-16997"},"relatedVulnerabilities":[{"id":"CVE-2017-16997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16997","cwe":"CWE-426","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16997","date":"2026-10-05","epss":0.02895,"percentile":0.86458}],"urls":["http://www.securityfocus.com/bid/102228","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://bugs.debian.org/884615","https://sourceware.org/bugzilla/show_bug.cgi?id=22625","https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16997","description":"elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the \"./\" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33574","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"risk":0.8622,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33574"},"relatedVulnerabilities":[{"id":"CVE-2021-33574","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210629-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=27896","https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33574","description":"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33574","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"risk":0.8622,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33574"},"relatedVulnerabilities":[{"id":"CVE-2021-33574","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210629-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=27896","https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33574","description":"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33574","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"risk":0.8622,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33574"},"relatedVulnerabilities":[{"id":"CVE-2021-33574","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33574","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-33574","date":"2026-10-05","epss":0.02874,"percentile":0.86358}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210629-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=27896","https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33574","description":"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"risk":0.847,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3997"},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"risk":0.847,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3997"},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"risk":0.847,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3997"},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"risk":0.847,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3997"},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-05","epss":0.01694,"percentile":0.7633}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15804","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15804","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"risk":0.8402999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15804"},"relatedVulnerabilities":[{"id":"CVE-2017-15804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"urls":["http://www.securityfocus.com/bid/101535","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22332","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15804","description":"The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15804","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15804","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"risk":0.8402999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15804"},"relatedVulnerabilities":[{"id":"CVE-2017-15804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"urls":["http://www.securityfocus.com/bid/101535","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22332","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15804","description":"The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-15804","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-15804","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"risk":0.8402999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-15804"},"relatedVulnerabilities":[{"id":"CVE-2017-15804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-15804","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-15804","date":"2026-10-05","epss":0.02801,"percentile":0.86002}],"urls":["http://www.securityfocus.com/bid/101535","https://access.redhat.com/errata/RHSA-2018:0805","https://access.redhat.com/errata/RHSA-2018:1879","https://sourceware.org/bugzilla/show_bug.cgi?id=22332","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=a159b53fa059947cc2548e3b0d5bdcf7b9630ba8"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15804","description":"The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15688","versionConstraint":"< 229-4ubuntu21.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15688","fix":{"state":"fixed","versions":["229-4ubuntu21.6"],"available":[{"date":"2018-11-05","kind":"advisory","version":"229-4ubuntu21.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"risk":0.8330000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15688"},"relatedVulnerabilities":[{"id":"CVE-2018-15688","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":6.5,"exploitabilityScore":6.5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"urls":["http://www.securityfocus.com/bid/105745","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3665","https://access.redhat.com/errata/RHSA-2019:0049","https://github.com/systemd/systemd/pull/10518","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3806-1/","https://usn.ubuntu.com/3807-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15688","description":"A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15688","versionConstraint":"< 229-4ubuntu21.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15688","fix":{"state":"fixed","versions":["229-4ubuntu21.6"],"available":[{"date":"2018-11-05","kind":"advisory","version":"229-4ubuntu21.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"risk":0.8330000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15688"},"relatedVulnerabilities":[{"id":"CVE-2018-15688","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":6.5,"exploitabilityScore":6.5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"urls":["http://www.securityfocus.com/bid/105745","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3665","https://access.redhat.com/errata/RHSA-2019:0049","https://github.com/systemd/systemd/pull/10518","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3806-1/","https://usn.ubuntu.com/3807-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15688","description":"A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-15688","versionConstraint":"< 229-4ubuntu21.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15688","fix":{"state":"fixed","versions":["229-4ubuntu21.6"],"available":[{"date":"2018-11-05","kind":"advisory","version":"229-4ubuntu21.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"risk":0.8330000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15688"},"relatedVulnerabilities":[{"id":"CVE-2018-15688","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":6.5,"exploitabilityScore":6.5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"urls":["http://www.securityfocus.com/bid/105745","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3665","https://access.redhat.com/errata/RHSA-2019:0049","https://github.com/systemd/systemd/pull/10518","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3806-1/","https://usn.ubuntu.com/3807-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15688","description":"A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15688","versionConstraint":"< 229-4ubuntu21.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15688","fix":{"state":"fixed","versions":["229-4ubuntu21.6"],"available":[{"date":"2018-11-05","kind":"advisory","version":"229-4ubuntu21.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"risk":0.8330000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15688"},"relatedVulnerabilities":[{"id":"CVE-2018-15688","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":6.5,"exploitabilityScore":6.5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15688","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15688","date":"2026-10-05","epss":0.01666,"percentile":0.75934}],"urls":["http://www.securityfocus.com/bid/105745","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3665","https://access.redhat.com/errata/RHSA-2019:0049","https://github.com/systemd/systemd/pull/10518","https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3806-1/","https://usn.ubuntu.com/3807-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15688","description":"A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239."}]},{"artifact":{"id":"72ed83bf5ce56df5","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.8-3.2ubuntu2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3238","versionConstraint":"< 1.1.8-3.2ubuntu2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-3238","fix":{"state":"fixed","versions":["1.1.8-3.2ubuntu2"],"available":[{"date":"2015-08-24","kind":"advisory","version":"1.1.8-3.2ubuntu2"}]},"cvss":[],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"risk":0.8115000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-3238"},"relatedVulnerabilities":[{"id":"CVE-2015-3238","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.html","http://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.html","http://rhn.redhat.com/errata/RHSA-2015-1640.html","http://www.openwall.com/lists/oss-security/2015/06/25/13","http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html","http://www.securityfocus.com/bid/75428","http://www.ubuntu.com/usn/USN-2935-1","http://www.ubuntu.com/usn/USN-2935-2","http://www.ubuntu.com/usn/USN-2935-3","https://bugzilla.redhat.com/show_bug.cgi?id=1228571","https://security.gentoo.org/glsa/201605-05","https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551","https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3238","description":"The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password."}]},{"artifact":{"id":"76d2edbbdcb350bc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.8-3.2ubuntu2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3238","versionConstraint":"< 1.1.8-3.2ubuntu2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-3238","fix":{"state":"fixed","versions":["1.1.8-3.2ubuntu2"],"available":[{"date":"2015-08-24","kind":"advisory","version":"1.1.8-3.2ubuntu2"}]},"cvss":[],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"risk":0.8115000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-3238"},"relatedVulnerabilities":[{"id":"CVE-2015-3238","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.html","http://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.html","http://rhn.redhat.com/errata/RHSA-2015-1640.html","http://www.openwall.com/lists/oss-security/2015/06/25/13","http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html","http://www.securityfocus.com/bid/75428","http://www.ubuntu.com/usn/USN-2935-1","http://www.ubuntu.com/usn/USN-2935-2","http://www.ubuntu.com/usn/USN-2935-3","https://bugzilla.redhat.com/show_bug.cgi?id=1228571","https://security.gentoo.org/glsa/201605-05","https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551","https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3238","description":"The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password."}]},{"artifact":{"id":"a55791055d3bc034","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.1.8-3.1ubuntu3?arch=all&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.8-3.2ubuntu2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3238","versionConstraint":"< 1.1.8-3.2ubuntu2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-3238","fix":{"state":"fixed","versions":["1.1.8-3.2ubuntu2"],"available":[{"date":"2015-08-24","kind":"advisory","version":"1.1.8-3.2ubuntu2"}]},"cvss":[],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"risk":0.8115000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-3238"},"relatedVulnerabilities":[{"id":"CVE-2015-3238","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.html","http://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.html","http://rhn.redhat.com/errata/RHSA-2015-1640.html","http://www.openwall.com/lists/oss-security/2015/06/25/13","http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html","http://www.securityfocus.com/bid/75428","http://www.ubuntu.com/usn/USN-2935-1","http://www.ubuntu.com/usn/USN-2935-2","http://www.ubuntu.com/usn/USN-2935-3","https://bugzilla.redhat.com/show_bug.cgi?id=1228571","https://security.gentoo.org/glsa/201605-05","https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551","https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3238","description":"The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password."}]},{"artifact":{"id":"0865b93c3edcb069","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.8-3.2ubuntu2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3238","versionConstraint":"< 1.1.8-3.2ubuntu2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2015-3238","fix":{"state":"fixed","versions":["1.1.8-3.2ubuntu2"],"available":[{"date":"2015-08-24","kind":"advisory","version":"1.1.8-3.2ubuntu2"}]},"cvss":[],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"risk":0.8115000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2015-3238"},"relatedVulnerabilities":[{"id":"CVE-2015-3238","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-3238","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-3238","date":"2026-10-05","epss":0.02705,"percentile":0.85458}],"urls":["http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161350.html","http://lists.fedoraproject.org/pipermail/package-announce/2015-June/161249.html","http://rhn.redhat.com/errata/RHSA-2015-1640.html","http://www.openwall.com/lists/oss-security/2015/06/25/13","http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html","http://www.securityfocus.com/bid/75428","http://www.ubuntu.com/usn/USN-2935-1","http://www.ubuntu.com/usn/USN-2935-2","http://www.ubuntu.com/usn/USN-2935-3","https://bugzilla.redhat.com/show_bug.cgi?id=1228571","https://security.gentoo.org/glsa/201605-05","https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-011/?fid=6551","https://www.trustwave.com/Resources/SpiderLabs-Blog/Username-Enumeration-against-OpenSSH-SELinux-with-CVE-2015-3238/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3238","description":"The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password."}]},{"artifact":{"id":"d14be6bc8e5294e4","cpes":["cpe:2.3:a:login:login:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12424","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12424","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-12424","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12424","date":"2026-10-05","epss":0.02659,"percentile":0.85189}],"risk":0.7977,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12424"},"relatedVulnerabilities":[{"id":"CVE-2017-12424","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12424","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12424","date":"2026-10-05","epss":0.02659,"percentile":0.85189}],"urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756630","https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1266675","https://github.com/shadow-maint/shadow/commit/954e3d2e7113e9ac06632aee3c69b8d818cc8952","https://lists.debian.org/debian-lts-announce/2021/03/msg00020.html","https://security.gentoo.org/glsa/201710-16"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12424","description":"In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts."}]},{"artifact":{"id":"f0c7bab4ad17922b","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12424","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12424","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-12424","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12424","date":"2026-10-05","epss":0.02659,"percentile":0.85189}],"risk":0.7977,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12424"},"relatedVulnerabilities":[{"id":"CVE-2017-12424","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12424","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12424","date":"2026-10-05","epss":0.02659,"percentile":0.85189}],"urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756630","https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1266675","https://github.com/shadow-maint/shadow/commit/954e3d2e7113e9ac06632aee3c69b8d818cc8952","https://lists.debian.org/debian-lts-announce/2021/03/msg00020.html","https://security.gentoo.org/glsa/201710-16"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12424","description":"In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts."}]},{"artifact":{"id":"ffff4bb59f135024","cpes":["cpe:2.3:a:libapparmor1:libapparmor1:2.10-0ubuntu11:*:*:*:*:*:*:*"],"name":"libapparmor1","purl":"pkg:deb/ubuntu/libapparmor1@2.10-0ubuntu11?arch=amd64&distro=ubuntu-16.04&upstream=apparmor","type":"deb","version":"2.10-0ubuntu11","language":"","licenses":["sha256:91a3a52df92c616db779d873ba90f0866221ffcc0396e5c42c28b5ae12ac511c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapparmor1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapparmor1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apparmor"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.95-0ubuntu2.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-6507","versionConstraint":"< 2.10.95-0ubuntu2.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apparmor","version":"2.10-0ubuntu11"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-6507","fix":{"state":"fixed","versions":["2.10.95-0ubuntu2.6"],"available":[{"date":"2017-03-28","kind":"advisory","version":"2.10.95-0ubuntu2.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-6507","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6507","date":"2026-10-05","epss":0.01589,"percentile":0.74799}],"risk":0.7945000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-6507"},"relatedVulnerabilities":[{"id":"CVE-2017-6507","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-6507","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6507","date":"2026-10-05","epss":0.01589,"percentile":0.74799}],"urls":["http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3647","http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3648","http://www.securityfocus.com/bid/97223","https://bugs.launchpad.net/apparmor/+bug/1668892","https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6507.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-6507","description":"An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic."}]},{"artifact":{"id":"29738ecc088f0593","cpes":["cpe:2.3:a:bash:bash:4.3-14ubuntu1:*:*:*:*:*:*:*"],"name":"bash","purl":"pkg:deb/ubuntu/bash@4.3-14ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"4.3-14ubuntu1","language":"","licenses":["sha256:da7a8d93abf1eccdeaf326642c8ce9ed760f3a973ca46f3f69b3cf755bb81ade"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bash/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/bash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.list"},{"path":"/var/lib/dpkg/info/bash.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postinst"},{"path":"/var/lib/dpkg/info/bash.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postrm"},{"path":"/var/lib/dpkg/info/bash.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.preinst"},{"path":"/var/lib/dpkg/info/bash.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-18276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"bash","version":"4.3-14ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-18276","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-18276","cwe":"CWE-273","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18276","cwe":"CWE-273","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18276","date":"2026-10-05","epss":0.02608,"percentile":0.84875}],"risk":0.7824,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-18276"},"relatedVulnerabilities":[{"id":"CVE-2019-18276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-18276","cwe":"CWE-273","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-18276","cwe":"CWE-273","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-18276","date":"2026-10-05","epss":0.02608,"percentile":0.84875}],"urls":["http://packetstormsecurity.com/files/155498/Bash-5.0-Patch-11-Privilege-Escalation.html","https://github.com/bminor/bash/commit/951bdaad7a18cc0dc1036bba86b18b90874d39ff","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://security.gentoo.org/glsa/202105-34","https://security.netapp.com/advisory/ntap-20200430-0003/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.youtube.com/watch?v=-wGtxJ8opa8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-18276","description":"An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support \"saved UID\" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use \"enable -f\" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35942","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-35942","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"risk":0.7814999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35942"},"relatedVulnerabilities":[{"id":"CVE-2021-35942","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://security.netapp.com/advisory/ntap-20210827-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=28011","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c","https://sourceware.org/glibc/wiki/Security%20Exceptions"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35942","description":"The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35942","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-35942","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"risk":0.7814999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35942"},"relatedVulnerabilities":[{"id":"CVE-2021-35942","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://security.netapp.com/advisory/ntap-20210827-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=28011","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c","https://sourceware.org/glibc/wiki/Security%20Exceptions"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35942","description":"The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35942","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-35942","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"risk":0.7814999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35942"},"relatedVulnerabilities":[{"id":"CVE-2021-35942","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35942","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-35942","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35942","date":"2026-10-05","epss":0.02605,"percentile":0.84857}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://security.netapp.com/advisory/ntap-20210827-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=28011","https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=5adda61f62b77384718b4c0d8336ade8f2b4b35c","https://sourceware.org/glibc/wiki/Security%20Exceptions"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35942","description":"The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-31484","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31484","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31484","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31484","date":"2026-10-05","epss":0.01548,"percentile":0.7419}],"risk":0.774,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-31484"},"relatedVulnerabilities":[{"id":"CVE-2023-31484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31484","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31484","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31484","date":"2026-10-05","epss":0.01548,"percentile":0.7419}],"urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/andk/cpanpm/pull/175","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BM6UW55CNFUTNGD5ZRKGUKKKFDJGMFHL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LEGCEOKFJVBJ2QQ6S2H4NAEWTUERC7SB/","https://metacpan.org/dist/CPAN/changes","https://security.netapp.com/advisory/ntap-20240621-0007/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://lists.debian.org/debian-lts-announce/2024/10/msg00017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31484","description":"CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS."}]},{"artifact":{"id":"2a02e042a2e2365e","cpes":["cpe:2.3:a:gnupg:gnupg:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.list"},{"path":"/var/lib/dpkg/info/gnupg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.postinst"},{"path":"/var/lib/dpkg/info/gnupg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.preinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-13050","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-13050","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-13050","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13050","date":"2026-10-05","epss":0.02524,"percentile":0.84334}],"risk":0.7571999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13050"},"relatedVulnerabilities":[{"id":"CVE-2019-13050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-13050","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13050","date":"2026-10-05","epss":0.02524,"percentile":0.84334}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00039.html","https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUK2YRO6QIH64WP2LRA5D4LACTXQPPU4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CP4ON34YEXEZDZOXXWV43KVGGO6WZLJ5/","https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html","https://support.f5.com/csp/article/K08654551","https://support.f5.com/csp/article/K08654551?utm_source=f5support&amp%3Butm_medium=RSS","https://twitter.com/lambdafu/status/1147162583969009664"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13050","description":"Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack."}]},{"artifact":{"id":"0418cef01c888ec2","cpes":["cpe:2.3:a:gpgv:gpgv:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gnupg","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-13050","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-13050","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-13050","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13050","date":"2026-10-05","epss":0.02524,"percentile":0.84334}],"risk":0.7571999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13050"},"relatedVulnerabilities":[{"id":"CVE-2019-13050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-13050","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13050","date":"2026-10-05","epss":0.02524,"percentile":0.84334}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00039.html","https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUK2YRO6QIH64WP2LRA5D4LACTXQPPU4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CP4ON34YEXEZDZOXXWV43KVGGO6WZLJ5/","https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html","https://support.f5.com/csp/article/K08654551","https://support.f5.com/csp/article/K08654551?utm_source=f5support&amp%3Butm_medium=RSS","https://twitter.com/lambdafu/status/1147162583969009664"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13050","description":"Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-48303","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-48303","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48303","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-48303","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-48303","date":"2026-10-05","epss":0.01476,"percentile":0.72952}],"risk":0.738,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48303"},"relatedVulnerabilities":[{"id":"CVE-2022-48303","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48303","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-48303","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-48303","date":"2026-10-05","epss":0.01476,"percentile":0.72952}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZNSVYDYYUD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7KXHLRZQS4/","https://savannah.gnu.org/bugs/?62387","https://savannah.gnu.org/patch/?10307"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48303","description":"GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12133","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12133","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"risk":0.7208999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12133"},"relatedVulnerabilities":[{"id":"CVE-2017-12133","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYZL6PAKI73XYRJYL5VLDGA4FFGWMB7A/","https://sourceware.org/bugzilla/show_bug.cgi?id=21115","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=d42eed4a044e5e10dfb885cf9891c2518a72a491","https://usn.ubuntu.com/4416-1/","https://www.securityfocus.com/bid/100679"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12133","description":"Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12133","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12133","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"risk":0.7208999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12133"},"relatedVulnerabilities":[{"id":"CVE-2017-12133","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYZL6PAKI73XYRJYL5VLDGA4FFGWMB7A/","https://sourceware.org/bugzilla/show_bug.cgi?id=21115","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=d42eed4a044e5e10dfb885cf9891c2518a72a491","https://usn.ubuntu.com/4416-1/","https://www.securityfocus.com/bid/100679"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12133","description":"Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12133","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12133","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"risk":0.7208999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12133"},"relatedVulnerabilities":[{"id":"CVE-2017-12133","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12133","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12133","date":"2026-10-05","epss":0.02403,"percentile":0.83472}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYZL6PAKI73XYRJYL5VLDGA4FFGWMB7A/","https://sourceware.org/bugzilla/show_bug.cgi?id=21115","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=d42eed4a044e5e10dfb885cf9891c2518a72a491","https://usn.ubuntu.com/4416-1/","https://www.securityfocus.com/bid/100679"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12133","description":"Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-40528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-40528","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-40528","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-40528","cwe":"CWE-327","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-40528","date":"2026-10-05","epss":0.01423,"percentile":0.71972}],"risk":0.7115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-40528"},"relatedVulnerabilities":[{"id":"CVE-2021-40528","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-40528","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-40528","cwe":"CWE-327","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-40528","date":"2026-10-05","epss":0.01423,"percentile":0.71972}],"urls":["https://eprint.iacr.org/2021/923","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=3462280f2e23e16adf3ed5176e0f2413d8861320","https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1","https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2","https://security.gentoo.org/glsa/202210-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-40528","description":"The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-6512","versionConstraint":"< 5.22.1-9ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-6512","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.3"],"available":[{"date":"2018-04-16","kind":"advisory","version":"5.22.1-9ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-6512","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6512","date":"2026-10-05","epss":0.02359,"percentile":0.8318}],"risk":0.7077,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-6512"},"relatedVulnerabilities":[{"id":"CVE-2017-6512","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-6512","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-6512","date":"2026-10-05","epss":0.02359,"percentile":0.8318}],"urls":["http://cpansearch.perl.org/src/JKEENAN/File-Path-2.13/Changes","http://security.cucumberlinux.com/security/details.php?id=153","http://www.debian.org/security/2017/dsa-3873","http://www.securityfocus.com/bid/99180","http://www.securitytracker.com/id/1038610","https://rt.cpan.org/Ticket/Display.html?id=121951","https://security.gentoo.org/glsa/201709-12","https://usn.ubuntu.com/3625-1/","https://usn.ubuntu.com/3625-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-6512","description":"Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-33560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-33560","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-33560","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33560","cwe":"CWE-325","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33560","date":"2026-10-05","epss":0.02342,"percentile":0.83047}],"risk":0.7026,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33560"},"relatedVulnerabilities":[{"id":"CVE-2021-33560","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33560","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33560","cwe":"CWE-325","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33560","date":"2026-10-05","epss":0.02342,"percentile":0.83047}],"urls":["https://dev.gnupg.org/T5305","https://dev.gnupg.org/T5328","https://dev.gnupg.org/T5466","https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61","https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/","https://security.gentoo.org/glsa/202210-13","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33560","description":"Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5-2ubuntu0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-9526","versionConstraint":"< 1.6.5-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-9526","fix":{"state":"fixed","versions":["1.6.5-2ubuntu0.3"],"available":[{"date":"2017-07-03","kind":"advisory","version":"1.6.5-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-9526","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9526","date":"2026-10-05","epss":0.02337,"percentile":0.83012}],"risk":0.7011,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-9526"},"relatedVulnerabilities":[{"id":"CVE-2017-9526","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9526","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9526","date":"2026-10-05","epss":0.02337,"percentile":0.83012}],"urls":["http://www.debian.org/security/2017/dsa-3880","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.securityfocus.com/bid/99046","https://bugzilla.suse.com/show_bug.cgi?id=1042326","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=5a22de904a0a366ae79f03ff1e13a1232a89e26b","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=f9494b3f258e01b6af8bd3941ce436bcc00afc56","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9526","description":"In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library."}]},{"artifact":{"id":"87cfee7645e64b8e","cpes":["cpe:2.3:a:e2fslibs:e2fslibs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fslibs","purl":"pkg:deb/ubuntu/e2fslibs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fslibs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fslibs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1304","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1304","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"risk":0.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1304"},"relatedVulnerabilities":[{"id":"CVE-2022-1304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2069726","https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html","https://security.netapp.com/advisory/ntap-20241122-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1304","description":"An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem."}]},{"artifact":{"id":"5a3ca5227318937c","cpes":["cpe:2.3:a:e2fsprogs:e2fsprogs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fsprogs","purl":"pkg:deb/ubuntu/e2fsprogs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fsprogs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fsprogs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.list"},{"path":"/var/lib/dpkg/info/e2fsprogs.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.preinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1304","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1304","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"risk":0.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1304"},"relatedVulnerabilities":[{"id":"CVE-2022-1304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2069726","https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html","https://security.netapp.com/advisory/ntap-20241122-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1304","description":"An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem."}]},{"artifact":{"id":"b1a41d82130bd387","cpes":["cpe:2.3:a:libcomerr2:libcomerr2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libcomerr2","purl":"pkg:deb/ubuntu/libcomerr2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:9e3a4384b6d8d2358d44103f62bcd948328b3f8a63a1a6baa66abeb43302d581"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcomerr2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcomerr2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1304","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1304","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"risk":0.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1304"},"relatedVulnerabilities":[{"id":"CVE-2022-1304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2069726","https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html","https://security.netapp.com/advisory/ntap-20241122-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1304","description":"An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem."}]},{"artifact":{"id":"149b9c41765f1d3e","cpes":["cpe:2.3:a:libss2:libss2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libss2","purl":"pkg:deb/ubuntu/libss2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:22363929a0275ab0f9c4de91c2fc39a49bdca25c21de3d32212614590918fd0f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libss2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libss2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libss2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libss2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1304","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-1304","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"risk":0.6965,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1304"},"relatedVulnerabilities":[{"id":"CVE-2022-1304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1304","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1304","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1304","date":"2026-10-05","epss":0.01393,"percentile":0.71434}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2069726","https://lists.debian.org/debian-lts-announce/2024/10/msg00001.html","https://security.netapp.com/advisory/ntap-20241122-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1304","description":"An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem."}]},{"artifact":{"id":"09f678f8187b6d3f","cpes":["cpe:2.3:a:apt:apt:1.1.10:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/ubuntu/apt@1.1.10?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.32ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-3810","versionConstraint":"< 1.2.32ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-3810","fix":{"state":"fixed","versions":["1.2.32ubuntu0.1"],"available":[{"date":"2020-05-14","kind":"advisory","version":"1.2.32ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-3810","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-3810","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-3810","date":"2026-10-05","epss":0.01338,"percentile":0.70289}],"risk":0.6689999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-3810"},"relatedVulnerabilities":[{"id":"CVE-2020-3810","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-3810","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-3810","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-3810","date":"2026-10-05","epss":0.01338,"percentile":0.70289}],"urls":["https://bugs.launchpad.net/bugs/1878177","https://github.com/Debian/apt/issues/111","https://lists.debian.org/debian-security-announce/2020/msg00089.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4PEH357MZM2SUGKETMEHMSGQS652QHH/","https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6","https://tracker.debian.org/news/1144109/accepted-apt-212-source-into-unstable/","https://usn.ubuntu.com/4359-1/","https://usn.ubuntu.com/4359-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-3810","description":"Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files."}]},{"artifact":{"id":"aba0f26b4d9c7fe4","cpes":["cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*"],"name":"libapt-pkg5.0","purl":"pkg:deb/ubuntu/libapt-pkg5.0@1.1.10?arch=amd64&distro=ubuntu-16.04&upstream=apt","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg5.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapt-pkg5.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.32ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-3810","versionConstraint":"< 1.2.32ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-3810","fix":{"state":"fixed","versions":["1.2.32ubuntu0.1"],"available":[{"date":"2020-05-14","kind":"advisory","version":"1.2.32ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-3810","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-3810","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-3810","date":"2026-10-05","epss":0.01338,"percentile":0.70289}],"risk":0.6689999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-3810"},"relatedVulnerabilities":[{"id":"CVE-2020-3810","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-3810","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-3810","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-3810","date":"2026-10-05","epss":0.01338,"percentile":0.70289}],"urls":["https://bugs.launchpad.net/bugs/1878177","https://github.com/Debian/apt/issues/111","https://lists.debian.org/debian-security-announce/2020/msg00089.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4PEH357MZM2SUGKETMEHMSGQS652QHH/","https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6","https://tracker.debian.org/news/1144109/accepted-apt-212-source-into-unstable/","https://usn.ubuntu.com/4359-1/","https://usn.ubuntu.com/4359-2/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-3810","description":"Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33599","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"risk":0.655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33599"},"relatedVulnerabilities":[{"id":"CVE-2024-33599","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0011/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33599","description":"nscd: Stack-based buffer overflow in netgroup cache\n\nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted\nby client requests then a subsequent client request for netgroup data\nmay result in a stack-based buffer overflow.  This flaw was introduced\nin glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33599","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"risk":0.655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33599"},"relatedVulnerabilities":[{"id":"CVE-2024-33599","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0011/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33599","description":"nscd: Stack-based buffer overflow in netgroup cache\n\nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted\nby client requests then a subsequent client request for netgroup data\nmay result in a stack-based buffer overflow.  This flaw was introduced\nin glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33599","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"risk":0.655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33599"},"relatedVulnerabilities":[{"id":"CVE-2024-33599","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2024-33599","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-33599","date":"2026-10-05","epss":0.0131,"percentile":0.69658}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0011/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33599","description":"nscd: Stack-based buffer overflow in netgroup cache\n\nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted\nby client requests then a subsequent client request for netgroup data\nmay result in a stack-based buffer overflow.  This flaw was introduced\nin glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"3453f479934eac05","cpes":["cpe:2.3:a:libprocps4:libprocps4:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"libprocps4","purl":"pkg:deb/ubuntu/libprocps4@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=procps","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libprocps4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libprocps4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libprocps4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1122","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1122","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1122","cwe":"CWE-829","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2018-1122","date":"2026-10-05","epss":0.01273,"percentile":0.68899}],"risk":0.6365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1122"},"relatedVulnerabilities":[{"id":"CVE-2018-1122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1122","cwe":"CWE-829","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2018-1122","date":"2026-10-05","epss":0.01273,"percentile":0.68899}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://access.redhat.com/errata/RHSA-2019:2189","https://access.redhat.com/errata/RHSA-2020:0595","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1122","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1122","description":"procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function."}]},{"artifact":{"id":"b2852edfb40d7492","cpes":["cpe:2.3:a:procps:procps:2\\:3.3.10-4ubuntu2:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/ubuntu/procps@2%3A3.3.10-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"2:3.3.10-4ubuntu2","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.3.10-4ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1122","versionConstraint":"< 2:3.3.10-4ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"procps","version":"2:3.3.10-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-1122","fix":{"state":"fixed","versions":["2:3.3.10-4ubuntu2.4"],"available":[{"date":"2018-05-23","kind":"advisory","version":"2:3.3.10-4ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1122","cwe":"CWE-829","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2018-1122","date":"2026-10-05","epss":0.01273,"percentile":0.68899}],"risk":0.6365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1122"},"relatedVulnerabilities":[{"id":"CVE-2018-1122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1122","cwe":"CWE-829","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2018-1122","date":"2026-10-05","epss":0.01273,"percentile":0.68899}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html","http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://access.redhat.com/errata/RHSA-2019:2189","https://access.redhat.com/errata/RHSA-2020:0595","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1122","https://lists.debian.org/debian-lts-announce/2018/05/msg00021.html","https://security.gentoo.org/glsa/201805-14","https://usn.ubuntu.com/3658-1/","https://usn.ubuntu.com/3658-3/","https://www.debian.org/security/2018/dsa-4208","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1122","description":"procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33600","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33600","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"risk":0.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33600"},"relatedVulnerabilities":[{"id":"CVE-2024-33600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0013/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33600","description":"nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference.  This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33600","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33600","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"risk":0.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33600"},"relatedVulnerabilities":[{"id":"CVE-2024-33600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0013/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33600","description":"nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference.  This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33600","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33600","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"risk":0.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33600"},"relatedVulnerabilities":[{"id":"CVE-2024-33600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33600","cwe":"CWE-476","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33600","date":"2026-10-05","epss":0.01216,"percentile":0.67555}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0013/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33600","description":"nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference.  This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3842","versionConstraint":"< 229-4ubuntu21.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3842","fix":{"state":"fixed","versions":["229-4ubuntu21.21"],"available":[{"date":"2019-04-08","kind":"advisory","version":"229-4ubuntu21.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"risk":0.6035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3842"},"relatedVulnerabilities":[{"id":"CVE-2019-3842","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/","https://www.exploit-db.com/exploits/46743/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3842","description":"In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the \"allow_active\" element rather than \"allow_any\"."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3842","versionConstraint":"< 229-4ubuntu21.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3842","fix":{"state":"fixed","versions":["229-4ubuntu21.21"],"available":[{"date":"2019-04-08","kind":"advisory","version":"229-4ubuntu21.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"risk":0.6035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3842"},"relatedVulnerabilities":[{"id":"CVE-2019-3842","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/","https://www.exploit-db.com/exploits/46743/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3842","description":"In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the \"allow_active\" element rather than \"allow_any\"."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-3842","versionConstraint":"< 229-4ubuntu21.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3842","fix":{"state":"fixed","versions":["229-4ubuntu21.21"],"available":[{"date":"2019-04-08","kind":"advisory","version":"229-4ubuntu21.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"risk":0.6035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3842"},"relatedVulnerabilities":[{"id":"CVE-2019-3842","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/","https://www.exploit-db.com/exploits/46743/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3842","description":"In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the \"allow_active\" element rather than \"allow_any\"."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-3842","versionConstraint":"< 229-4ubuntu21.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-3842","fix":{"state":"fixed","versions":["229-4ubuntu21.21"],"available":[{"date":"2019-04-08","kind":"advisory","version":"229-4ubuntu21.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"risk":0.6035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-3842"},"relatedVulnerabilities":[{"id":"CVE-2019-3842","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-3842","cwe":"CWE-285","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-3842","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-3842","date":"2026-10-05","epss":0.01207,"percentile":0.67319}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/","https://www.exploit-db.com/exploits/46743/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-3842","description":"In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the \"allow_active\" element rather than \"allow_any\"."}]},{"artifact":{"id":"42899f1499942b30","cpes":["cpe:2.3:a:libpcre3:libpcre3:2\\:8.38-1ubuntu1:*:*:*:*:*:*:*"],"name":"libpcre3","purl":"pkg:deb/ubuntu/libpcre3@2%3A8.38-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=pcre3","type":"deb","version":"2:8.38-1ubuntu1","language":"","licenses":["sha256:ac9276490d2fa167442ae1aae33926514ad10c8886baa40046c5e367fccc5938"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpcre3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-7244","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pcre3","version":"2:8.38-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-7244","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-7244","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7244","date":"2026-10-05","epss":0.01995,"percentile":0.79993}],"risk":0.5985,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-7244"},"relatedVulnerabilities":[{"id":"CVE-2017-7244","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-7244","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-7244","date":"2026-10-05","epss":0.01995,"percentile":0.79993}],"urls":["http://www.securityfocus.com/bid/97067","https://access.redhat.com/errata/RHSA-2018:2486","https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/","https://security.gentoo.org/glsa/201710-25"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7244","description":"The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12132","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12132","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"risk":0.5874,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12132"},"relatedVulnerabilities":[{"id":"CVE-2017-12132","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"urls":["http://www.securityfocus.com/bid/100598","https://access.redhat.com/errata/RHSA-2018:0805","https://arxiv.org/pdf/1205.4011.pdf","https://sourceware.org/bugzilla/show_bug.cgi?id=21361"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12132","description":"The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12132","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12132","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"risk":0.5874,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12132"},"relatedVulnerabilities":[{"id":"CVE-2017-12132","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"urls":["http://www.securityfocus.com/bid/100598","https://access.redhat.com/errata/RHSA-2018:0805","https://arxiv.org/pdf/1205.4011.pdf","https://sourceware.org/bugzilla/show_bug.cgi?id=21361"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12132","description":"The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-12132","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-12132","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"risk":0.5874,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-12132"},"relatedVulnerabilities":[{"id":"CVE-2017-12132","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-12132","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-12132","date":"2026-10-05","epss":0.01958,"percentile":0.79614}],"urls":["http://www.securityfocus.com/bid/100598","https://access.redhat.com/errata/RHSA-2018:0805","https://arxiv.org/pdf/1205.4011.pdf","https://sourceware.org/bugzilla/show_bug.cgi?id=21361"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-12132","description":"The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4813","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4813","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"risk":0.5778,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4813"},"relatedVulnerabilities":[{"id":"CVE-2023-4813","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"urls":["https://access.redhat.com/errata/RHBA-2024:2413","https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4813","https://bugzilla.redhat.com/show_bug.cgi?id=2237798","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://security.netapp.com/advisory/ntap-20231110-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4813","description":"A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4813","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4813","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"risk":0.5778,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4813"},"relatedVulnerabilities":[{"id":"CVE-2023-4813","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"urls":["https://access.redhat.com/errata/RHBA-2024:2413","https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4813","https://bugzilla.redhat.com/show_bug.cgi?id=2237798","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://security.netapp.com/advisory/ntap-20231110-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4813","description":"A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4813","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4813","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"risk":0.5778,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4813"},"relatedVulnerabilities":[{"id":"CVE-2023-4813","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4813","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4813","date":"2026-10-05","epss":0.01926,"percentile":0.79251}],"urls":["https://access.redhat.com/errata/RHBA-2024:2413","https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4813","https://bugzilla.redhat.com/show_bug.cgi?id=2237798","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://security.netapp.com/advisory/ntap-20231110-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4813","description":"A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge."}]},{"artifact":{"id":"87cfee7645e64b8e","cpes":["cpe:2.3:a:e2fslibs:e2fslibs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fslibs","purl":"pkg:deb/ubuntu/e2fslibs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fslibs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fslibs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5094","versionConstraint":"< 1.42.13-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5094","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.1"],"available":[{"date":"2019-09-30","kind":"advisory","version":"1.42.13-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"risk":0.5525,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5094"},"relatedVulnerabilities":[{"id":"CVE-2019-5094","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"urls":["https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://seclists.org/bugtraq/2019/Sep/58","https://security.gentoo.org/glsa/202003-05","https://security.netapp.com/advisory/ntap-20200115-0002/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0887","https://usn.ubuntu.com/4142-1/","https://usn.ubuntu.com/4142-2/","https://www.debian.org/security/2019/dsa-4535"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5094","description":"An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"5a3ca5227318937c","cpes":["cpe:2.3:a:e2fsprogs:e2fsprogs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fsprogs","purl":"pkg:deb/ubuntu/e2fsprogs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fsprogs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fsprogs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.list"},{"path":"/var/lib/dpkg/info/e2fsprogs.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5094","versionConstraint":"< 1.42.13-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5094","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.1"],"available":[{"date":"2019-09-30","kind":"advisory","version":"1.42.13-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"risk":0.5525,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5094"},"relatedVulnerabilities":[{"id":"CVE-2019-5094","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"urls":["https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://seclists.org/bugtraq/2019/Sep/58","https://security.gentoo.org/glsa/202003-05","https://security.netapp.com/advisory/ntap-20200115-0002/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0887","https://usn.ubuntu.com/4142-1/","https://usn.ubuntu.com/4142-2/","https://www.debian.org/security/2019/dsa-4535"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5094","description":"An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"b1a41d82130bd387","cpes":["cpe:2.3:a:libcomerr2:libcomerr2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libcomerr2","purl":"pkg:deb/ubuntu/libcomerr2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:9e3a4384b6d8d2358d44103f62bcd948328b3f8a63a1a6baa66abeb43302d581"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcomerr2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcomerr2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5094","versionConstraint":"< 1.42.13-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5094","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.1"],"available":[{"date":"2019-09-30","kind":"advisory","version":"1.42.13-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"risk":0.5525,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5094"},"relatedVulnerabilities":[{"id":"CVE-2019-5094","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"urls":["https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://seclists.org/bugtraq/2019/Sep/58","https://security.gentoo.org/glsa/202003-05","https://security.netapp.com/advisory/ntap-20200115-0002/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0887","https://usn.ubuntu.com/4142-1/","https://usn.ubuntu.com/4142-2/","https://www.debian.org/security/2019/dsa-4535"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5094","description":"An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"149b9c41765f1d3e","cpes":["cpe:2.3:a:libss2:libss2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libss2","purl":"pkg:deb/ubuntu/libss2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:22363929a0275ab0f9c4de91c2fc39a49bdca25c21de3d32212614590918fd0f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libss2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libss2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libss2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libss2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5094","versionConstraint":"< 1.42.13-1ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5094","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.1"],"available":[{"date":"2019-09-30","kind":"advisory","version":"1.42.13-1ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"risk":0.5525,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5094"},"relatedVulnerabilities":[{"id":"CVE-2019-5094","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2019-5094","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-5094","date":"2026-10-05","epss":0.01105,"percentile":0.6463}],"urls":["https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://seclists.org/bugtraq/2019/Sep/58","https://security.gentoo.org/glsa/202003-05","https://security.netapp.com/advisory/ntap-20200115-0002/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0887","https://usn.ubuntu.com/4142-1/","https://usn.ubuntu.com/4142-2/","https://www.debian.org/security/2019/dsa-4535"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5094","description":"An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33601","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33601","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"risk":0.5375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33601"},"relatedVulnerabilities":[{"id":"CVE-2024-33601","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0014/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33601","description":"nscd: netgroup cache may terminate daemon on memory allocation failure\n\nThe Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or\nxrealloc and these functions may terminate the process due to a memory\nallocation failure resulting in a denial of service to the clients.  The\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33601","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33601","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"risk":0.5375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33601"},"relatedVulnerabilities":[{"id":"CVE-2024-33601","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0014/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33601","description":"nscd: netgroup cache may terminate daemon on memory allocation failure\n\nThe Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or\nxrealloc and these functions may terminate the process due to a memory\nallocation failure resulting in a denial of service to the clients.  The\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33601","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33601","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"risk":0.5375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33601"},"relatedVulnerabilities":[{"id":"CVE-2024-33601","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33601","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33601","date":"2026-10-05","epss":0.01075,"percentile":0.63804}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0014/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33601","description":"nscd: netgroup cache may terminate daemon on memory allocation failure\n\nThe Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or\nxrealloc and these functions may terminate the process due to a memory\nallocation failure resulting in a denial of service to the clients.  The\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16864","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16864","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"risk":0.53325,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16864"},"relatedVulnerabilities":[{"id":"CVE-2018-16864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106523","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16864","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16864","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16864","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"risk":0.53325,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16864"},"relatedVulnerabilities":[{"id":"CVE-2018-16864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106523","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16864","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-16864","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16864","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"risk":0.53325,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16864"},"relatedVulnerabilities":[{"id":"CVE-2018-16864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106523","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16864","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16864","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16864","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"risk":0.53325,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16864"},"relatedVulnerabilities":[{"id":"CVE-2018-16864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16864","cwe":"CWE-770","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16864","date":"2026-10-05","epss":0.00711,"percentile":0.51954}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/20/2","http://www.securityfocus.com/bid/106523","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2019:0049","https://access.redhat.com/errata/RHSA-2019:0204","https://access.redhat.com/errata/RHSA-2019:0271","https://access.redhat.com/errata/RHSA-2019:0342","https://access.redhat.com/errata/RHSA-2019:0361","https://access.redhat.com/errata/RHSA-2019:2402","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864","https://lists.debian.org/debian-lts-announce/2019/01/msg00016.html","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16864","description":"An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15687","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15687","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"risk":0.529,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15687"},"relatedVulnerabilities":[{"id":"CVE-2018-15687","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"urls":["http://www.securityfocus.com/bid/105748","https://github.com/systemd/systemd/pull/10517/commits","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45715/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15687","description":"A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15687","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15687","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"risk":0.529,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15687"},"relatedVulnerabilities":[{"id":"CVE-2018-15687","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"urls":["http://www.securityfocus.com/bid/105748","https://github.com/systemd/systemd/pull/10517/commits","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45715/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15687","description":"A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-15687","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15687","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"risk":0.529,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15687"},"relatedVulnerabilities":[{"id":"CVE-2018-15687","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"urls":["http://www.securityfocus.com/bid/105748","https://github.com/systemd/systemd/pull/10517/commits","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45715/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15687","description":"A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15687","versionConstraint":"< 229-4ubuntu21.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-15687","fix":{"state":"fixed","versions":["229-4ubuntu21.8"],"available":[{"date":"2018-11-12","kind":"advisory","version":"229-4ubuntu21.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"risk":0.529,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-15687"},"relatedVulnerabilities":[{"id":"CVE-2018-15687","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15687","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15687","date":"2026-10-05","epss":0.01058,"percentile":0.63306}],"urls":["http://www.securityfocus.com/bid/105748","https://github.com/systemd/systemd/pull/10517/commits","https://security.gentoo.org/glsa/201810-10","https://usn.ubuntu.com/3816-1/","https://www.exploit-db.com/exploits/45715/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15687","description":"A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16866","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16866","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"risk":0.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16866"},"relatedVulnerabilities":[{"id":"CVE-2018-16866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.securityfocus.com/bid/106527","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16866","description":"An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16866","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16866","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"risk":0.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16866"},"relatedVulnerabilities":[{"id":"CVE-2018-16866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.securityfocus.com/bid/106527","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16866","description":"An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-16866","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16866","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"risk":0.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16866"},"relatedVulnerabilities":[{"id":"CVE-2018-16866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.securityfocus.com/bid/106527","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16866","description":"An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16866","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-16866","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"risk":0.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16866"},"relatedVulnerabilities":[{"id":"CVE-2018-16866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16866","cwe":"CWE-125","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16866","date":"2026-10-05","epss":0.01051,"percentile":0.63084}],"urls":["http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html","http://seclists.org/fulldisclosure/2019/May/21","http://www.openwall.com/lists/oss-security/2019/05/10/4","http://www.securityfocus.com/bid/106527","https://access.redhat.com/errata/RHSA-2019:2091","https://access.redhat.com/errata/RHSA-2019:3222","https://access.redhat.com/errata/RHSA-2020:0593","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866","https://seclists.org/bugtraq/2019/May/25","https://security.gentoo.org/glsa/201903-07","https://security.netapp.com/advisory/ntap-20190117-0001/","https://usn.ubuntu.com/3855-1/","https://www.debian.org/security/2019/dsa-4367","https://www.qualys.com/2019/01/09/system-down/system-down.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16866","description":"An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable."}]},{"artifact":{"id":"ffff4bb59f135024","cpes":["cpe:2.3:a:libapparmor1:libapparmor1:2.10-0ubuntu11:*:*:*:*:*:*:*"],"name":"libapparmor1","purl":"pkg:deb/ubuntu/libapparmor1@2.10-0ubuntu11?arch=amd64&distro=ubuntu-16.04&upstream=apparmor","type":"deb","version":"2.10-0ubuntu11","language":"","licenses":["sha256:91a3a52df92c616db779d873ba90f0866221ffcc0396e5c42c28b5ae12ac511c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapparmor1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapparmor1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apparmor"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apparmor","version":"2.10-0ubuntu11"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1585","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2016-1585","date":"2026-10-05","epss":0.01034,"percentile":0.62624}],"risk":0.517,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1585"},"relatedVulnerabilities":[{"id":"CVE-2016-1585","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":3.4,"exploitabilityScore":0.5},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-1585","date":"2026-10-05","epss":0.01034,"percentile":0.62624}],"urls":["https://bugs.launchpad.net/apparmor/+bug/1597017","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1585","description":"In all versions of AppArmor mount rules are accidentally widened when compiled."}]},{"artifact":{"id":"87cfee7645e64b8e","cpes":["cpe:2.3:a:e2fslibs:e2fslibs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fslibs","purl":"pkg:deb/ubuntu/e2fslibs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fslibs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fslibs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fslibs:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5188","versionConstraint":"< 1.42.13-1ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5188","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.2"],"available":[{"date":"2020-01-23","kind":"advisory","version":"1.42.13-1ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"risk":0.5125000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5188"},"relatedVulnerabilities":[{"id":"CVE-2019-5188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html","https://lists.debian.org/debian-lts-announce/2020/03/msg00030.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://security.netapp.com/advisory/ntap-20220506-0001/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973","https://usn.ubuntu.com/4249-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5188","description":"A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"5a3ca5227318937c","cpes":["cpe:2.3:a:e2fsprogs:e2fsprogs:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"e2fsprogs","purl":"pkg:deb/ubuntu/e2fsprogs@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:ab9a71b44fb79b213558705781261c504ecd5da67718039f3c53e8635371567b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/e2fsprogs/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/e2fsprogs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/e2fsprogs.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.list"},{"path":"/var/lib/dpkg/info/e2fsprogs.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/e2fsprogs.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-5188","versionConstraint":"< 1.42.13-1ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5188","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.2"],"available":[{"date":"2020-01-23","kind":"advisory","version":"1.42.13-1ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"risk":0.5125000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5188"},"relatedVulnerabilities":[{"id":"CVE-2019-5188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html","https://lists.debian.org/debian-lts-announce/2020/03/msg00030.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://security.netapp.com/advisory/ntap-20220506-0001/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973","https://usn.ubuntu.com/4249-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5188","description":"A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"b1a41d82130bd387","cpes":["cpe:2.3:a:libcomerr2:libcomerr2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libcomerr2","purl":"pkg:deb/ubuntu/libcomerr2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:9e3a4384b6d8d2358d44103f62bcd948328b3f8a63a1a6baa66abeb43302d581"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcomerr2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcomerr2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcomerr2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5188","versionConstraint":"< 1.42.13-1ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5188","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.2"],"available":[{"date":"2020-01-23","kind":"advisory","version":"1.42.13-1ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"risk":0.5125000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5188"},"relatedVulnerabilities":[{"id":"CVE-2019-5188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html","https://lists.debian.org/debian-lts-announce/2020/03/msg00030.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://security.netapp.com/advisory/ntap-20220506-0001/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973","https://usn.ubuntu.com/4249-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5188","description":"A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"149b9c41765f1d3e","cpes":["cpe:2.3:a:libss2:libss2:1.42.13-1ubuntu1:*:*:*:*:*:*:*"],"name":"libss2","purl":"pkg:deb/ubuntu/libss2@1.42.13-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=e2fsprogs","type":"deb","version":"1.42.13-1ubuntu1","language":"","licenses":["sha256:22363929a0275ab0f9c4de91c2fc39a49bdca25c21de3d32212614590918fd0f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libss2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libss2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libss2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libss2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"e2fsprogs"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.42.13-1ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-5188","versionConstraint":"< 1.42.13-1ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"e2fsprogs","version":"1.42.13-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-5188","fix":{"state":"fixed","versions":["1.42.13-1ubuntu1.2"],"available":[{"date":"2020-01-23","kind":"advisory","version":"1.42.13-1ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"risk":0.5125000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-5188"},"relatedVulnerabilities":[{"id":"CVE-2019-5188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2019-5188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-5188","date":"2026-10-05","epss":0.01025,"percentile":0.62343}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html","https://lists.debian.org/debian-lts-announce/2020/03/msg00030.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY/","https://security.netapp.com/advisory/ntap-20220506-0001/","https://talosintelligence.com/vulnerability_reports/TALOS-2019-0973","https://usn.ubuntu.com/4249-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-5188","description":"A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4806","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"risk":0.4818,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4806"},"relatedVulnerabilities":[{"id":"CVE-2023-4806","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"urls":["https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4806","https://bugzilla.redhat.com/show_bug.cgi?id=2237782","http://www.openwall.com/lists/oss-security/2023/10/03/4","http://www.openwall.com/lists/oss-security/2023/10/03/5","http://www.openwall.com/lists/oss-security/2023/10/03/6","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/","https://security.gentoo.org/glsa/202310-03","https://security.netapp.com/advisory/ntap-20240125-0008/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-831302.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4806","description":"A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4806","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"risk":0.4818,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4806"},"relatedVulnerabilities":[{"id":"CVE-2023-4806","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"urls":["https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4806","https://bugzilla.redhat.com/show_bug.cgi?id=2237782","http://www.openwall.com/lists/oss-security/2023/10/03/4","http://www.openwall.com/lists/oss-security/2023/10/03/5","http://www.openwall.com/lists/oss-security/2023/10/03/6","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/","https://security.gentoo.org/glsa/202310-03","https://security.netapp.com/advisory/ntap-20240125-0008/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-831302.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4806","description":"A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4806","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"risk":0.4818,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4806"},"relatedVulnerabilities":[{"id":"CVE-2023-4806","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4806","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4806","date":"2026-10-05","epss":0.01606,"percentile":0.75051}],"urls":["https://access.redhat.com/errata/RHSA-2023:5453","https://access.redhat.com/errata/RHSA-2023:5455","https://access.redhat.com/errata/RHSA-2023:7409","https://access.redhat.com/security/cve/CVE-2023-4806","https://bugzilla.redhat.com/show_bug.cgi?id=2237782","http://www.openwall.com/lists/oss-security/2023/10/03/4","http://www.openwall.com/lists/oss-security/2023/10/03/5","http://www.openwall.com/lists/oss-security/2023/10/03/6","http://www.openwall.com/lists/oss-security/2023/10/03/8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/","https://security.gentoo.org/glsa/202310-03","https://security.netapp.com/advisory/ntap-20240125-0008/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-831302.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4806","description":"A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags."}]},{"artifact":{"id":"d14be6bc8e5294e4","cpes":["cpe:2.3:a:login:login:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-7169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-7169","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-7169","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-7169","date":"2026-10-05","epss":0.01566,"percentile":0.74456}],"risk":0.4698,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-7169"},"relatedVulnerabilities":[{"id":"CVE-2018-7169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-7169","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-7169","date":"2026-10-05","epss":0.01566,"percentile":0.74456}],"urls":["https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1729357","https://security.gentoo.org/glsa/201805-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-7169","description":"An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation."}]},{"artifact":{"id":"f0c7bab4ad17922b","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-7169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-7169","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-7169","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-7169","date":"2026-10-05","epss":0.01566,"percentile":0.74456}],"risk":0.4698,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-7169"},"relatedVulnerabilities":[{"id":"CVE-2018-7169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-7169","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-7169","date":"2026-10-05","epss":0.01566,"percentile":0.74456}],"urls":["https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1729357","https://security.gentoo.org/glsa/201805-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-7169","description":"An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-29491","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-29491","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"risk":0.4655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-29491"},"relatedVulnerabilities":[{"id":"CVE-2023-29491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"urls":["http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","http://www.openwall.com/lists/oss-security/2023/04/19/10","http://www.openwall.com/lists/oss-security/2023/04/19/11","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://security.netapp.com/advisory/ntap-20230517-0009/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845","https://www.openwall.com/lists/oss-security/2023/04/12/5","https://www.openwall.com/lists/oss-security/2023/04/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","description":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-29491","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-29491","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"risk":0.4655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-29491"},"relatedVulnerabilities":[{"id":"CVE-2023-29491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"urls":["http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","http://www.openwall.com/lists/oss-security/2023/04/19/10","http://www.openwall.com/lists/oss-security/2023/04/19/11","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://security.netapp.com/advisory/ntap-20230517-0009/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845","https://www.openwall.com/lists/oss-security/2023/04/12/5","https://www.openwall.com/lists/oss-security/2023/04/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","description":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-29491","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-29491","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"risk":0.4655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-29491"},"relatedVulnerabilities":[{"id":"CVE-2023-29491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"urls":["http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","http://www.openwall.com/lists/oss-security/2023/04/19/10","http://www.openwall.com/lists/oss-security/2023/04/19/11","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://security.netapp.com/advisory/ntap-20230517-0009/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845","https://www.openwall.com/lists/oss-security/2023/04/12/5","https://www.openwall.com/lists/oss-security/2023/04/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","description":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-29491","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-29491","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"risk":0.4655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-29491"},"relatedVulnerabilities":[{"id":"CVE-2023-29491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"urls":["http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","http://www.openwall.com/lists/oss-security/2023/04/19/10","http://www.openwall.com/lists/oss-security/2023/04/19/11","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://security.netapp.com/advisory/ntap-20230517-0009/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845","https://www.openwall.com/lists/oss-security/2023/04/12/5","https://www.openwall.com/lists/oss-security/2023/04/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","description":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-29491","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-29491","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"risk":0.4655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-29491"},"relatedVulnerabilities":[{"id":"CVE-2023-29491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29491","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29491","date":"2026-10-05","epss":0.00931,"percentile":0.59279}],"urls":["http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","http://www.openwall.com/lists/oss-security/2023/04/19/10","http://www.openwall.com/lists/oss-security/2023/04/19/11","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://security.netapp.com/advisory/ntap-20230517-0009/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845","https://www.openwall.com/lists/oss-security/2023/04/12/5","https://www.openwall.com/lists/oss-security/2023/04/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","description":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11237","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11237","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"risk":0.44,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11237"},"relatedVulnerabilities":[{"id":"CVE-2018-11237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"urls":["http://www.securityfocus.com/bid/104256","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=23196","https://usn.ubuntu.com/4416-1/","https://www.exploit-db.com/exploits/44750/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11237","description":"An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11237","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11237","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"risk":0.44,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11237"},"relatedVulnerabilities":[{"id":"CVE-2018-11237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"urls":["http://www.securityfocus.com/bid/104256","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=23196","https://usn.ubuntu.com/4416-1/","https://www.exploit-db.com/exploits/44750/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11237","description":"An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11237","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-11237","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"risk":0.44,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11237"},"relatedVulnerabilities":[{"id":"CVE-2018-11237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11237","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11237","date":"2026-10-05","epss":0.0088,"percentile":0.57711}],"urls":["http://www.securityfocus.com/bid/104256","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=23196","https://usn.ubuntu.com/4416-1/","https://www.exploit-db.com/exploits/44750/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11237","description":"An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000408","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000408","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"risk":0.43499999999999994,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000408"},"relatedVulnerabilities":[{"id":"CVE-2017-1000408","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"urls":["http://seclists.org/oss-sec/2017/q4/385","http://www.openwall.com/lists/oss-security/2019/06/27/7","http://www.openwall.com/lists/oss-security/2019/06/28/1","http://www.openwall.com/lists/oss-security/2019/06/28/2","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000408","description":"A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000408","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000408","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"risk":0.43499999999999994,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000408"},"relatedVulnerabilities":[{"id":"CVE-2017-1000408","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"urls":["http://seclists.org/oss-sec/2017/q4/385","http://www.openwall.com/lists/oss-security/2019/06/27/7","http://www.openwall.com/lists/oss-security/2019/06/28/1","http://www.openwall.com/lists/oss-security/2019/06/28/2","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000408","description":"A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000408","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000408","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"risk":0.43499999999999994,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000408"},"relatedVulnerabilities":[{"id":"CVE-2017-1000408","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000408","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000408","date":"2026-10-05","epss":0.0145,"percentile":0.72477}],"urls":["http://seclists.org/oss-sec/2017/q4/385","http://www.openwall.com/lists/oss-security/2019/06/27/7","http://www.openwall.com/lists/oss-security/2019/06/28/1","http://www.openwall.com/lists/oss-security/2019/06/28/2","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000408","description":"A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7796","versionConstraint":"< 229-4ubuntu11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7796","fix":{"state":"fixed","versions":["229-4ubuntu11"],"available":[{"date":"2016-10-13","kind":"advisory","version":"229-4ubuntu11"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"risk":0.4275,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7796"},"relatedVulnerabilities":[{"id":"CVE-2016-7796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html","http://rhn.redhat.com/errata/RHSA-2017-0003.html","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93250","http://www.securitytracker.com/id/1037320","https://bugzilla.redhat.com/show_bug.cgi?id=1381911","https://github.com/systemd/systemd/issues/4234#issuecomment-250441246","https://rhn.redhat.com/errata/RHBA-2015-2092.html","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7796","description":"The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7796","versionConstraint":"< 229-4ubuntu11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7796","fix":{"state":"fixed","versions":["229-4ubuntu11"],"available":[{"date":"2016-10-13","kind":"advisory","version":"229-4ubuntu11"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"risk":0.4275,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7796"},"relatedVulnerabilities":[{"id":"CVE-2016-7796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html","http://rhn.redhat.com/errata/RHSA-2017-0003.html","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93250","http://www.securitytracker.com/id/1037320","https://bugzilla.redhat.com/show_bug.cgi?id=1381911","https://github.com/systemd/systemd/issues/4234#issuecomment-250441246","https://rhn.redhat.com/errata/RHBA-2015-2092.html","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7796","description":"The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-7796","versionConstraint":"< 229-4ubuntu11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7796","fix":{"state":"fixed","versions":["229-4ubuntu11"],"available":[{"date":"2016-10-13","kind":"advisory","version":"229-4ubuntu11"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"risk":0.4275,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7796"},"relatedVulnerabilities":[{"id":"CVE-2016-7796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html","http://rhn.redhat.com/errata/RHSA-2017-0003.html","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93250","http://www.securitytracker.com/id/1037320","https://bugzilla.redhat.com/show_bug.cgi?id=1381911","https://github.com/systemd/systemd/issues/4234#issuecomment-250441246","https://rhn.redhat.com/errata/RHBA-2015-2092.html","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7796","description":"The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7796","versionConstraint":"< 229-4ubuntu11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7796","fix":{"state":"fixed","versions":["229-4ubuntu11"],"available":[{"date":"2016-10-13","kind":"advisory","version":"229-4ubuntu11"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"risk":0.4275,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7796"},"relatedVulnerabilities":[{"id":"CVE-2016-7796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7796","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7796","date":"2026-10-05","epss":0.00855,"percentile":0.56929}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00015.html","http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00016.html","http://rhn.redhat.com/errata/RHSA-2017-0003.html","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93250","http://www.securitytracker.com/id/1037320","https://bugzilla.redhat.com/show_bug.cgi?id=1381911","https://github.com/systemd/systemd/issues/4234#issuecomment-250441246","https://rhn.redhat.com/errata/RHBA-2015-2092.html","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7796","description":"The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-4415","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"risk":0.4235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4415"},"relatedVulnerabilities":[{"id":"CVE-2022-4415","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"urls":["https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9c","https://www.openwall.com/lists/oss-security/2022/12/21/3","http://seclists.org/fulldisclosure/2025/Jun/9","https://security.netapp.com/advisory/ntap-20230216-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4415","description":"A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-4415","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"risk":0.4235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4415"},"relatedVulnerabilities":[{"id":"CVE-2022-4415","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"urls":["https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9c","https://www.openwall.com/lists/oss-security/2022/12/21/3","http://seclists.org/fulldisclosure/2025/Jun/9","https://security.netapp.com/advisory/ntap-20230216-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4415","description":"A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-4415","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"risk":0.4235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4415"},"relatedVulnerabilities":[{"id":"CVE-2022-4415","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"urls":["https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9c","https://www.openwall.com/lists/oss-security/2022/12/21/3","http://seclists.org/fulldisclosure/2025/Jun/9","https://security.netapp.com/advisory/ntap-20230216-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4415","description":"A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-4415","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"risk":0.4235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4415"},"relatedVulnerabilities":[{"id":"CVE-2022-4415","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4415","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4415","date":"2026-10-05","epss":0.00847,"percentile":0.56628}],"urls":["https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9c","https://www.openwall.com/lists/oss-security/2022/12/21/3","http://seclists.org/fulldisclosure/2025/Jun/9","https://security.netapp.com/advisory/ntap-20230216-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4415","description":"A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-13529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-13529","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13529"},"relatedVulnerabilities":[{"id":"CVE-2020-13529","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.9,"impactScore":2.9,"exploitabilityScore":5.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20210625-0005/","https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13529","description":"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-13529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-13529","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13529"},"relatedVulnerabilities":[{"id":"CVE-2020-13529","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.9,"impactScore":2.9,"exploitabilityScore":5.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20210625-0005/","https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13529","description":"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-13529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-13529","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13529"},"relatedVulnerabilities":[{"id":"CVE-2020-13529","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.9,"impactScore":2.9,"exploitabilityScore":5.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20210625-0005/","https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13529","description":"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-13529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-13529","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13529"},"relatedVulnerabilities":[{"id":"CVE-2020-13529","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:A/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.9,"impactScore":2.9,"exploitabilityScore":5.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-13529","cwe":"CWE-290","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13529","date":"2026-10-05","epss":0.01399,"percentile":0.71533}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20210625-0005/","https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13529","description":"An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-4176","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4176","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-4176","date":"2026-10-05","epss":0.00811,"percentile":0.55483}],"risk":0.40549999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4176"},"relatedVulnerabilities":[{"id":"CVE-2026-4176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4176","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-4176","date":"2026-10-05","epss":0.00811,"percentile":0.55483}],"urls":["https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94","https://lists.security.metacpan.org/cve-announce/msg/37638919/","https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes","https://metacpan.org/release/SHAY/perl-5.40.4/changes","https://metacpan.org/release/SHAY/perl-5.42.2/changes","https://www.cve.org/CVERecord?id=CVE-2026-3381","http://www.openwall.com/lists/oss-security/2026/03/30/2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4176","description":"Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.\n\nCompress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-16156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-16156","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-16156","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-16156","date":"2026-10-05","epss":0.00798,"percentile":0.55011}],"risk":0.39899999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-16156"},"relatedVulnerabilities":[{"id":"CVE-2020-16156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-16156","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-16156","date":"2026-10-05","epss":0.00798,"percentile":0.55011}],"urls":["http://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html","https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SD6RYOJII7HRJ6WVORFNVTYNOFY5JDXN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SZ32AJIV4RHJMLWLU5QULGKMMIHYOMDC/","https://metacpan.org/pod/distribution/CPAN/scripts/cpan","https://lists.debian.org/debian-lts-announce/2024/10/msg00017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-16156","description":"CPAN 2.28 allows Signature Verification Bypass."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-1238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-1238","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-1238","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1238","date":"2026-10-05","epss":0.00779,"percentile":0.54373}],"risk":0.3895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-1238"},"relatedVulnerabilities":[{"id":"CVE-2016-1238","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1238","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-1238","date":"2026-10-05","epss":0.00779,"percentile":0.54373}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html","http://perl5.git.perl.org/perl.git/commit/cee96d52c39b1e7b36e1c62d38bcd8d86e9a41ab","http://www.debian.org/security/2016/dsa-3628","http://www.nntp.perl.org/group/perl.perl5.porters/2016/07/msg238271.html","http://www.securityfocus.com/bid/92136","http://www.securitytracker.com/id/1036440","https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731","https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c%40%3Cannounce.apache.org%3E","https://lists.debian.org/debian-lts-announce/2018/11/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2FBQOCV3GBAN2EYZUM3CFDJ4ECA3GZOK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOFRQWJRP2NQJEYEWOMECVW3HAMD5SYN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZBNQH3DMI7HDELJAZ4TFJJANHXOEDWH/","https://rt.perl.org/Public/Bug/Display.html?id=127834","https://security.gentoo.org/glsa/201701-75","https://security.gentoo.org/glsa/201812-07"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1238","description":"(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-10043","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2011-10043","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-10043","cwe":"CWE-145","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2011-10043","date":"2026-10-05","epss":0.00775,"percentile":0.54236}],"risk":0.3875,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2011-10043"},"relatedVulnerabilities":[{"id":"CVE-2011-10043","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-10043","cwe":"CWE-145","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2011-10043","date":"2026-10-05","epss":0.00775,"percentile":0.54236}],"urls":["https://blogs.perl.org/users/michael_g_schwern/2011/10/how-not-to-load-a-module-or-bad-interfaces-make-good-people-do-bad-things.html","https://metacpan.org/release/BINGOS/Module-Load-0.22/changes","https://metacpan.org/release/BINGOS/Module-Load-0.22/diff/BINGOS/Module-Load-0.20/lib/Module/Load.pm"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-10043","description":"Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded.\n\nModule names starting with \"::\" could be passed to the load function to specify arbitrary module paths.\n\nAttackers able to influence module names passed to load could use that bug to execute arbitrary code."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3999","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"risk":0.373,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3999"},"relatedVulnerabilities":[{"id":"CVE-2021-3999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3999","https://bugzilla.redhat.com/show_bug.cgi?id=2024637","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security-tracker.debian.org/tracker/CVE-2021-3999","https://security.netapp.com/advisory/ntap-20221104-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=28769","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e","https://www.openwall.com/lists/oss-security/2022/01/24/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3999","description":"A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3999","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"risk":0.373,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3999"},"relatedVulnerabilities":[{"id":"CVE-2021-3999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3999","https://bugzilla.redhat.com/show_bug.cgi?id=2024637","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security-tracker.debian.org/tracker/CVE-2021-3999","https://security.netapp.com/advisory/ntap-20221104-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=28769","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e","https://www.openwall.com/lists/oss-security/2022/01/24/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3999","description":"A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-3999","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"risk":0.373,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3999"},"relatedVulnerabilities":[{"id":"CVE-2021-3999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3999","cwe":"CWE-193","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3999","date":"2026-10-05","epss":0.00746,"percentile":0.53219}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3999","https://bugzilla.redhat.com/show_bug.cgi?id=2024637","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security-tracker.debian.org/tracker/CVE-2021-3999","https://security.netapp.com/advisory/ntap-20221104-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=28769","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=23e0e8f5f1fb5ed150253d986ecccdc90c2dcd5e","https://www.openwall.com/lists/oss-security/2022/01/24/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3999","description":"A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000409","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000409","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"risk":0.3624,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000409"},"relatedVulnerabilities":[{"id":"CVE-2017-1000409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"urls":["http://seclists.org/oss-sec/2017/q4/385","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000409","description":"A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000409","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000409","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"risk":0.3624,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000409"},"relatedVulnerabilities":[{"id":"CVE-2017-1000409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"urls":["http://seclists.org/oss-sec/2017/q4/385","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000409","description":"A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-1000409","versionConstraint":"< 2.23-0ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-1000409","fix":{"state":"fixed","versions":["2.23-0ubuntu10"],"available":[{"date":"2018-01-17","kind":"advisory","version":"2.23-0ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"risk":0.3624,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-1000409"},"relatedVulnerabilities":[{"id":"CVE-2017-1000409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":6.9,"impactScore":10.1,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-1000409","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-1000409","date":"2026-10-05","epss":0.01208,"percentile":0.67328}],"urls":["http://seclists.org/oss-sec/2017/q4/385","https://security.netapp.com/advisory/ntap-20190404-0003/","https://www.exploit-db.com/exploits/43331/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000409","description":"A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5450"},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5450"},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5450"},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-05","epss":0.00718,"percentile":0.52255}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19217","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"risk":0.34769999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19217"},"relatedVulnerabilities":[{"id":"CVE-2018-19217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643753"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19217","description":"In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party"}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19217","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"risk":0.34769999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19217"},"relatedVulnerabilities":[{"id":"CVE-2018-19217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643753"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19217","description":"In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party"}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19217","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"risk":0.34769999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19217"},"relatedVulnerabilities":[{"id":"CVE-2018-19217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643753"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19217","description":"In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party"}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19217","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"risk":0.34769999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19217"},"relatedVulnerabilities":[{"id":"CVE-2018-19217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643753"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19217","description":"In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party"}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19217","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19217","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"risk":0.34769999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19217"},"relatedVulnerabilities":[{"id":"CVE-2018-19217","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19217","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19217","date":"2026-10-05","epss":0.01159,"percentile":0.65999}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643753"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19217","description":"In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party"}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-2236","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-05","epss":0.01114,"percentile":0.64868}],"risk":0.3342,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2236"},"relatedVulnerabilities":[{"id":"CVE-2024-2236","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-05","epss":0.01114,"percentile":0.64868}],"urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4046"},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4046"},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4046"},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-05","epss":0.00662,"percentile":0.4995}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-20193","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-20193","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20193","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-20193","date":"2026-10-05","epss":0.01092,"percentile":0.64251}],"risk":0.3276,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-20193"},"relatedVulnerabilities":[{"id":"CVE-2021-20193","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20193","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-20193","date":"2026-10-05","epss":0.01092,"percentile":0.64251}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1917565","https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777","https://savannah.gnu.org/bugs/?59897","https://security.gentoo.org/glsa/202105-29"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-20193","description":"A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"2a02e042a2e2365e","cpes":["cpe:2.3:a:gnupg:gnupg:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.list"},{"path":"/var/lib/dpkg/info/gnupg.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.postinst"},{"path":"/var/lib/dpkg/info/gnupg.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gnupg.preinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-14855","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-14855","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14855","date":"2026-10-05","epss":0.01077,"percentile":0.63841}],"risk":0.3231,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-14855"},"relatedVulnerabilities":[{"id":"CVE-2019-14855","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14855","date":"2026-10-05","epss":0.01077,"percentile":0.63841}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14855","https://dev.gnupg.org/T4755","https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html","https://rwc.iacr.org/2020/slides/Leurent.pdf","https://usn.ubuntu.com/4516-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14855","description":"A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18."}]},{"artifact":{"id":"0418cef01c888ec2","cpes":["cpe:2.3:a:gpgv:gpgv:1.4.19-6ubuntu1:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@1.4.19-6ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gnupg","type":"deb","version":"1.4.19-6ubuntu1","language":"","licenses":["GPL-3","GPL-3+","RFC-Reference"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-14855","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gnupg","version":"1.4.19-6ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-14855","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14855","date":"2026-10-05","epss":0.01077,"percentile":0.63841}],"risk":0.3231,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-14855"},"relatedVulnerabilities":[{"id":"CVE-2019-14855","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14855","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14855","date":"2026-10-05","epss":0.01077,"percentile":0.63841}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14855","https://dev.gnupg.org/T4755","https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html","https://rwc.iacr.org/2020/slides/Leurent.pdf","https://usn.ubuntu.com/4516-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14855","description":"A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-20230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-20230","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-20230","cwe":"CWE-121","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2017-20230","date":"2026-10-05","epss":0.00641,"percentile":0.48932}],"risk":0.3205,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-20230"},"relatedVulnerabilities":[{"id":"CVE-2017-20230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-20230","cwe":"CWE-121","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2017-20230","date":"2026-10-05","epss":0.00641,"percentile":0.48932}],"urls":["https://github.com/Perl/perl5/commit/a258c17c6937f79529c8319a829310e09cdbd216.patch","https://github.com/Perl/perl5/issues/15831","https://metacpan.org/release/RURBAN/Storable-3.05/changes","https://www.nntp.perl.org/group/perl.perl5.porters/2017/01/msg242533.html","https://www.nntp.perl.org/group/perl.perl5.porters/2017/01/msg242703.html","http://www.openwall.com/lists/oss-security/2026/04/21/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-20230","description":"Storable versions before 3.05 for Perl has a stack overflow.\n\nThe retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18078","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18078","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"risk":0.3195,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18078"},"relatedVulnerabilities":[{"id":"CVE-2017-18078","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"urls":["http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html","http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html","http://www.openwall.com/lists/oss-security/2018/01/29/3","https://github.com/systemd/systemd/issues/7736","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://www.exploit-db.com/exploits/43935/","https://www.openwall.com/lists/oss-security/2018/01/29/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18078","description":"systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18078","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18078","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"risk":0.3195,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18078"},"relatedVulnerabilities":[{"id":"CVE-2017-18078","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"urls":["http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html","http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html","http://www.openwall.com/lists/oss-security/2018/01/29/3","https://github.com/systemd/systemd/issues/7736","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://www.exploit-db.com/exploits/43935/","https://www.openwall.com/lists/oss-security/2018/01/29/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18078","description":"systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-18078","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18078","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"risk":0.3195,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18078"},"relatedVulnerabilities":[{"id":"CVE-2017-18078","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"urls":["http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html","http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html","http://www.openwall.com/lists/oss-security/2018/01/29/3","https://github.com/systemd/systemd/issues/7736","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://www.exploit-db.com/exploits/43935/","https://www.openwall.com/lists/oss-security/2018/01/29/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18078","description":"systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-18078","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-18078","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"risk":0.3195,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-18078"},"relatedVulnerabilities":[{"id":"CVE-2017-18078","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18078","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18078","date":"2026-10-05","epss":0.01065,"percentile":0.63499}],"urls":["http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html","http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html","http://www.openwall.com/lists/oss-security/2018/01/29/3","https://github.com/systemd/systemd/issues/7736","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html","https://www.exploit-db.com/exploits/43935/","https://www.openwall.com/lists/oss-security/2018/01/29/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18078","description":"systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-26604","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-26604","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"risk":0.3153,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-26604"},"relatedVulnerabilities":[{"id":"CVE-2023-26604","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"urls":["http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html","https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/","https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340","https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html","https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7","https://security.netapp.com/advisory/ntap-20230505-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26604","description":"systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the \"systemctl status\" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-26604","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-26604","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"risk":0.3153,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-26604"},"relatedVulnerabilities":[{"id":"CVE-2023-26604","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"urls":["http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html","https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/","https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340","https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html","https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7","https://security.netapp.com/advisory/ntap-20230505-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26604","description":"systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the \"systemctl status\" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-26604","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-26604","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"risk":0.3153,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-26604"},"relatedVulnerabilities":[{"id":"CVE-2023-26604","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"urls":["http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html","https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/","https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340","https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html","https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7","https://security.netapp.com/advisory/ntap-20230505-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26604","description":"systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the \"systemctl status\" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-26604","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-26604","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"risk":0.3153,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-26604"},"relatedVulnerabilities":[{"id":"CVE-2023-26604","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-26604","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-26604","date":"2026-10-05","epss":0.01051,"percentile":0.6309}],"urls":["http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html","https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/","https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340","https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html","https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7","https://security.netapp.com/advisory/ntap-20230505-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26604","description":"systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the \"systemctl status\" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-05","epss":0.0063,"percentile":0.48377}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-05","epss":0.0063,"percentile":0.48377}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7795","versionConstraint":"< 229-4ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7795","fix":{"state":"fixed","versions":["229-4ubuntu10"],"available":[{"date":"2016-09-29","kind":"advisory","version":"229-4ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"risk":0.314,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7795"},"relatedVulnerabilities":[{"id":"CVE-2016-7795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2610.html","http://rhn.redhat.com/errata/RHSA-2016-2694.html","http://www.openwall.com/lists/oss-security/2016/09/28/9","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93223","http://www.securitytracker.com/id/1037320","http://www.ubuntu.com/usn/USN-3094-1","https://github.com/systemd/systemd/issues/4234","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7795","description":"The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7795","versionConstraint":"< 229-4ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7795","fix":{"state":"fixed","versions":["229-4ubuntu10"],"available":[{"date":"2016-09-29","kind":"advisory","version":"229-4ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"risk":0.314,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7795"},"relatedVulnerabilities":[{"id":"CVE-2016-7795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2610.html","http://rhn.redhat.com/errata/RHSA-2016-2694.html","http://www.openwall.com/lists/oss-security/2016/09/28/9","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93223","http://www.securitytracker.com/id/1037320","http://www.ubuntu.com/usn/USN-3094-1","https://github.com/systemd/systemd/issues/4234","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7795","description":"The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-7795","versionConstraint":"< 229-4ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7795","fix":{"state":"fixed","versions":["229-4ubuntu10"],"available":[{"date":"2016-09-29","kind":"advisory","version":"229-4ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"risk":0.314,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7795"},"relatedVulnerabilities":[{"id":"CVE-2016-7795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2610.html","http://rhn.redhat.com/errata/RHSA-2016-2694.html","http://www.openwall.com/lists/oss-security/2016/09/28/9","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93223","http://www.securitytracker.com/id/1037320","http://www.ubuntu.com/usn/USN-3094-1","https://github.com/systemd/systemd/issues/4234","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7795","description":"The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-7795","versionConstraint":"< 229-4ubuntu10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7795","fix":{"state":"fixed","versions":["229-4ubuntu10"],"available":[{"date":"2016-09-29","kind":"advisory","version":"229-4ubuntu10"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"risk":0.314,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7795"},"relatedVulnerabilities":[{"id":"CVE-2016-7795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7795","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7795","date":"2026-10-05","epss":0.00628,"percentile":0.48282}],"urls":["http://rhn.redhat.com/errata/RHSA-2016-2610.html","http://rhn.redhat.com/errata/RHSA-2016-2694.html","http://www.openwall.com/lists/oss-security/2016/09/28/9","http://www.openwall.com/lists/oss-security/2016/09/30/1","http://www.securityfocus.com/bid/93223","http://www.securitytracker.com/id/1037320","http://www.ubuntu.com/usn/USN-3094-1","https://github.com/systemd/systemd/issues/4234","https://www.agwa.name/blog/post/how_to_crash_systemd_in_one_tweet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7795","description":"The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"risk":0.3135,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0915"},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"risk":0.3135,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0915"},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"risk":0.3135,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0915"},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-05","epss":0.00627,"percentile":0.48257}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"2916ecd7c14c26b2","cpes":["cpe:2.3:a:gcc-5-base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5-base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"gcc-5-base","purl":"pkg:deb/ubuntu/gcc-5-base@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gcc-5-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-23026","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-23026","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"risk":0.312,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-23026"},"relatedVulnerabilities":[{"id":"CVE-2020-23026","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"urls":["https://fossies.org/linux/privat/old/dhrystone-2.1.tar.gz/dhry_1.c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-23026","description":"A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS)."}]},{"artifact":{"id":"ea776ff124db708b","cpes":["cpe:2.3:a:libgcc1:libgcc1:1\\:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libgcc1","purl":"pkg:deb/ubuntu/libgcc1@1%3A5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5%405.3.1-7ubuntu1","type":"deb","version":"1:5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcc1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5","version":"5.3.1-7ubuntu1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-23026","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-23026","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"risk":0.312,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-23026"},"relatedVulnerabilities":[{"id":"CVE-2020-23026","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"urls":["https://fossies.org/linux/privat/old/dhrystone-2.1.tar.gz/dhry_1.c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-23026","description":"A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS)."}]},{"artifact":{"id":"ef656887b7b17615","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/ubuntu/libstdc%2B%2B6@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-23026","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-23026","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"risk":0.312,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-23026"},"relatedVulnerabilities":[{"id":"CVE-2020-23026","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-23026","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-23026","date":"2026-10-05","epss":0.0104,"percentile":0.62764}],"urls":["https://fossies.org/linux/privat/old/dhrystone-2.1.tar.gz/dhry_1.c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-23026","description":"A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS)."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-05","epss":0.00609,"percentile":0.47356}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48959"},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-05","epss":0.00609,"percentile":0.47356}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"61fb1a5a2a17f1ab","cpes":["cpe:2.3:a:mawk:mawk:1.3.3-17ubuntu2:*:*:*:*:*:*:*"],"name":"mawk","purl":"pkg:deb/ubuntu/mawk@1.3.3-17ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.3.3-17ubuntu2","language":"","licenses":["sha256:80910bdabaf183ae4d3ffd72d9fe9066a9a1035be8e5d7dd541ddc6755d19abb"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mawk/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/mawk/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mawk.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mawk.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mawk.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mawk.list"},{"path":"/var/lib/dpkg/info/mawk.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mawk.postinst"},{"path":"/var/lib/dpkg/info/mawk.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/mawk.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-20229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"mawk","version":"1.3.3-17ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-20229","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-20229","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2017-20229","date":"2026-10-05","epss":0.00602,"percentile":0.4696}],"risk":0.301,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-20229"},"relatedVulnerabilities":[{"id":"CVE-2017-20229","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-20229","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2017-20229","date":"2026-10-05","epss":0.00602,"percentile":0.4696}],"urls":["https://www.exploit-db.com/exploits/42357","https://www.vulncheck.com/advisories/mawk-17-stack-based-buffer-overflow"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-20229","description":"MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges."}]},{"artifact":{"id":"140c93cc6171b04a","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2ubuntu4:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.8.dfsg-2ubuntu4?arch=amd64&distro=ubuntu-16.04&upstream=zlib","type":"deb","version":"1:1.2.8.dfsg-2ubuntu4","language":"","licenses":["sha256:bcf07f8f2414e28405b35fee95fb14569e926a7d4e99cc4a5db2fe1a0d1aca56"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"zlib","version":"1:1.2.8.dfsg-2ubuntu4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-05","epss":0.00592,"percentile":0.46441}],"risk":0.296,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-05","epss":0.00592,"percentile":0.46441}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"fd49eba6fbc47fe8","cpes":["cpe:2.3:a:libcap2:libcap2:1\\:2.24-12:*:*:*:*:*:*:*"],"name":"libcap2","purl":"pkg:deb/ubuntu/libcap2@1%3A2.24-12?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1:2.24-12","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcap2/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcap2:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-2603","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libcap2","version":"1:2.24-12"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-2603","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-2603","date":"2026-10-05","epss":0.00579,"percentile":0.45746}],"risk":0.2895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2603"},"relatedVulnerabilities":[{"id":"CVE-2023-2603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-2603","date":"2026-10-05","epss":0.00579,"percentile":0.45746}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2209113","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/","https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2603","description":"A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB."}]},{"artifact":{"id":"d06f230212fe583b","cpes":["cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.24-12:*:*:*:*:*:*:*","cpe:2.3:a:libcap2-bin:libcap2_bin:1\\:2.24-12:*:*:*:*:*:*:*","cpe:2.3:a:libcap2_bin:libcap2-bin:1\\:2.24-12:*:*:*:*:*:*:*","cpe:2.3:a:libcap2_bin:libcap2_bin:1\\:2.24-12:*:*:*:*:*:*:*","cpe:2.3:a:libcap2:libcap2-bin:1\\:2.24-12:*:*:*:*:*:*:*","cpe:2.3:a:libcap2:libcap2_bin:1\\:2.24-12:*:*:*:*:*:*:*"],"name":"libcap2-bin","purl":"pkg:deb/ubuntu/libcap2-bin@1%3A2.24-12?arch=amd64&distro=ubuntu-16.04&upstream=libcap2","type":"deb","version":"1:2.24-12","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcap2-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcap2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcap2-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcap2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcap2-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcap2-bin.list"}],"upstreams":[{"name":"libcap2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2603","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libcap2","version":"1:2.24-12"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-2603","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-2603","date":"2026-10-05","epss":0.00579,"percentile":0.45746}],"risk":0.2895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2603"},"relatedVulnerabilities":[{"id":"CVE-2023-2603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2603","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-2603","date":"2026-10-05","epss":0.00579,"percentile":0.45746}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2209113","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/","https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2603","description":"A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"risk":0.2886,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-50495"},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"risk":0.2886,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-50495"},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"risk":0.2886,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-50495"},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"risk":0.2886,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-50495"},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"risk":0.2886,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-50495"},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-05","epss":0.00962,"percentile":0.60304}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"29738ecc088f0593","cpes":["cpe:2.3:a:bash:bash:4.3-14ubuntu1:*:*:*:*:*:*:*"],"name":"bash","purl":"pkg:deb/ubuntu/bash@4.3-14ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"4.3-14ubuntu1","language":"","licenses":["sha256:da7a8d93abf1eccdeaf326642c8ce9ed760f3a973ca46f3f69b3cf755bb81ade"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bash/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/bash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bash.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.list"},{"path":"/var/lib/dpkg/info/bash.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postinst"},{"path":"/var/lib/dpkg/info/bash.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.postrm"},{"path":"/var/lib/dpkg/info/bash.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.preinst"},{"path":"/var/lib/dpkg/info/bash.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/bash.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.3-14ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-7543","versionConstraint":"< 4.3-14ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"bash","version":"4.3-14ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-7543","fix":{"state":"fixed","versions":["4.3-14ubuntu1.2"],"available":[{"date":"2017-05-17","kind":"advisory","version":"4.3-14ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-7543","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7543","date":"2026-10-05","epss":0.00576,"percentile":0.45581}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-7543"},"relatedVulnerabilities":[{"id":"CVE-2016-7543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7543","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7543","date":"2026-10-05","epss":0.00576,"percentile":0.45581}],"urls":["http://rhn.redhat.com/errata/RHSA-2017-0725.html","http://www.openwall.com/lists/oss-security/2016/09/26/9","http://www.securityfocus.com/bid/93183","http://www.securitytracker.com/id/1037812","https://access.redhat.com/errata/RHSA-2017:1931","https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/","https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.html","https://security.gentoo.org/glsa/201701-02"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7543","description":"Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20796"},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20796"},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20796"},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-05","epss":0.05757,"percentile":0.9285}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"c190d32df7482157","cpes":["cpe:2.3:a:gzip:gzip:1.6-4ubuntu1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.6-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6-4ubuntu1","language":"","licenses":["sha256:f9ac4a5d7a670e3891881a2cdba5fa2cd625c4d58eae4a7aa372ac00a06803bd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gzip","version":"1.6-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-05","epss":0.00564,"percentile":0.44936}],"risk":0.28200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41992"},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-05","epss":0.00564,"percentile":0.44936}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"bbf8a50c5579e908","cpes":["cpe:2.3:a:libdb5.3:libdb5.3:5.3.28-11:*:*:*:*:*:*:*"],"name":"libdb5.3","purl":"pkg:deb/ubuntu/libdb5.3@5.3.28-11?arch=amd64&distro=ubuntu-16.04&upstream=db5.3","type":"deb","version":"5.3.28-11","language":"","licenses":["sha256:b3bbc6fbb3f2a0e6a487e953eb8c3cc4bdb6f4150f7f51d20b1e9a3c8ef92d3d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdb5.3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libdb5.3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libdb5.3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"db5.3"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.3.28-11ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10140","versionConstraint":"< 5.3.28-11ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"db5.3","version":"5.3.28-11"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10140","fix":{"state":"fixed","versions":["5.3.28-11ubuntu0.1"],"available":[{"date":"2017-11-21","kind":"advisory","version":"5.3.28-11ubuntu0.1"}]},"cvss":[],"epss":[{"cve":"CVE-2017-10140","date":"2026-10-05","epss":0.00547,"percentile":0.43922}],"risk":0.2735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10140"},"relatedVulnerabilities":[{"id":"CVE-2017-10140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-10140","date":"2026-10-05","epss":0.00547,"percentile":0.43922}],"urls":["http://seclists.org/oss-sec/2017/q3/285","http://www.postfix.org/announcements/postfix-3.2.2.html","https://access.redhat.com/errata/RHSA-2019:0366","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10140","description":"Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1751","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1751","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"risk":0.26849999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1751"},"relatedVulnerabilities":[{"id":"CVE-2020-1751","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:C","metrics":{"baseScore":5.9,"impactScore":8.6,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200430-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=25423","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1751","description":"An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1751","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1751","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"risk":0.26849999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1751"},"relatedVulnerabilities":[{"id":"CVE-2020-1751","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:C","metrics":{"baseScore":5.9,"impactScore":8.6,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200430-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=25423","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1751","description":"An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1751","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1751","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"risk":0.26849999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1751"},"relatedVulnerabilities":[{"id":"CVE-2020-1751","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:C","metrics":{"baseScore":5.9,"impactScore":8.6,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1751","date":"2026-10-05","epss":0.00537,"percentile":0.43296}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1751","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200430-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=25423","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1751","description":"An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5-2ubuntu0.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-0495","versionConstraint":"< 1.6.5-2ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-0495","fix":{"state":"fixed","versions":["1.6.5-2ubuntu0.5"],"available":[{"date":"2018-06-19","kind":"advisory","version":"1.6.5-2ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-0495","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-0495","date":"2026-10-05","epss":0.00887,"percentile":0.57912}],"risk":0.26609999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-0495"},"relatedVulnerabilities":[{"id":"CVE-2018-0495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-0495","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-0495","date":"2026-10-05","epss":0.00887,"percentile":0.57912}],"urls":["http://www.securitytracker.com/id/1041144","http://www.securitytracker.com/id/1041147","https://access.redhat.com/errata/RHSA-2018:3221","https://access.redhat.com/errata/RHSA-2018:3505","https://access.redhat.com/errata/RHSA-2019:1296","https://access.redhat.com/errata/RHSA-2019:1297","https://access.redhat.com/errata/RHSA-2019:1543","https://access.redhat.com/errata/RHSA-2019:2237","https://dev.gnupg.org/T4011","https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=9010d1576e278a4274ad3f4aa15776c28f6ba965","https://lists.debian.org/debian-lts-announce/2018/06/msg00013.html","https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000426.html","https://usn.ubuntu.com/3689-1/","https://usn.ubuntu.com/3689-2/","https://usn.ubuntu.com/3692-1/","https://usn.ubuntu.com/3692-2/","https://usn.ubuntu.com/3850-1/","https://usn.ubuntu.com/3850-2/","https://www.debian.org/security/2018/dsa-4231","https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-0495","description":"Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-27618","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"risk":0.26609999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27618"},"relatedVulnerabilities":[{"id":"CVE-2020-27618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210401-0006/","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27618","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-27618","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"risk":0.26609999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27618"},"relatedVulnerabilities":[{"id":"CVE-2020-27618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210401-0006/","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27618","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-27618","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"risk":0.26609999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27618"},"relatedVulnerabilities":[{"id":"CVE-2020-27618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-27618","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-27618","date":"2026-10-05","epss":0.00887,"percentile":0.57904}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202107-07","https://security.netapp.com/advisory/ntap-20210401-0006/","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27618","description":"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6954","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6954","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"risk":0.2625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6954"},"relatedVulnerabilities":[{"id":"CVE-2018-6954","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","https://github.com/systemd/systemd/issues/7986","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://usn.ubuntu.com/3816-1/","https://usn.ubuntu.com/3816-2/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6954","description":"systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6954","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6954","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"risk":0.2625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6954"},"relatedVulnerabilities":[{"id":"CVE-2018-6954","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","https://github.com/systemd/systemd/issues/7986","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://usn.ubuntu.com/3816-1/","https://usn.ubuntu.com/3816-2/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6954","description":"systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6954","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6954","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"risk":0.2625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6954"},"relatedVulnerabilities":[{"id":"CVE-2018-6954","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","https://github.com/systemd/systemd/issues/7986","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://usn.ubuntu.com/3816-1/","https://usn.ubuntu.com/3816-2/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6954","description":"systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-6954","versionConstraint":"< 229-4ubuntu21.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-6954","fix":{"state":"fixed","versions":["229-4ubuntu21.15"],"available":[{"date":"2019-01-11","kind":"advisory","version":"229-4ubuntu21.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"risk":0.2625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6954"},"relatedVulnerabilities":[{"id":"CVE-2018-6954","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-6954","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-6954","date":"2026-10-05","epss":0.00525,"percentile":0.42499}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html","https://github.com/systemd/systemd/issues/7986","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://usn.ubuntu.com/3816-1/","https://usn.ubuntu.com/3816-2/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6954","description":"systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"risk":0.2589,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19211"},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"risk":0.2589,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19211"},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"risk":0.2589,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19211"},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"risk":0.2589,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19211"},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"risk":0.2589,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19211"},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-05","epss":0.00863,"percentile":0.57187}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"39f1fcda5d7f8075","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.4-5:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.4-5?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.6.4-5","language":"","licenses":["sha256:02bd435c1907708f6c29deb79411fcae1fd18eed6d7b2624d94053435c22b75b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5-2ubuntu0.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-13627","versionConstraint":"< 1.6.5-2ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"libgcrypt20","version":"1.6.4-5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2019-13627","fix":{"state":"fixed","versions":["1.6.5-2ubuntu0.6"],"available":[{"date":"2020-01-14","kind":"advisory","version":"1.6.5-2ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-13627","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13627","date":"2026-10-05","epss":0.0051,"percentile":0.4147}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13627"},"relatedVulnerabilities":[{"id":"CVE-2019-13627","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":5,"exploitabilityScore":2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-13627","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13627","date":"2026-10-05","epss":0.0051,"percentile":0.4147}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00060.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00018.html","http://www.openwall.com/lists/oss-security/2019/10/02/2","https://github.com/gpg/libgcrypt/releases/tag/libgcrypt-1.8.5","https://lists.debian.org/debian-lts-announce/2019/09/msg00024.html","https://lists.debian.org/debian-lts-announce/2020/01/msg00001.html","https://minerva.crocs.fi.muni.cz/","https://security-tracker.debian.org/tracker/CVE-2019-13627","https://security.gentoo.org/glsa/202003-32","https://usn.ubuntu.com/4236-1/","https://usn.ubuntu.com/4236-2/","https://usn.ubuntu.com/4236-3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13627","description":"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-7008","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-7008","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"risk":0.2547,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-7008"},"relatedVulnerabilities":[{"id":"CVE-2023-7008","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"urls":["https://access.redhat.com/errata/RHSA-2024:2463","https://access.redhat.com/errata/RHSA-2024:3203","https://access.redhat.com/security/cve/CVE-2023-7008","https://bugzilla.redhat.com/show_bug.cgi?id=2222261","https://bugzilla.redhat.com/show_bug.cgi?id=2222672","https://github.com/systemd/systemd/issues/25676","https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/","https://security.netapp.com/advisory/ntap-20241122-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-7008","description":"A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-7008","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-7008","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"risk":0.2547,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-7008"},"relatedVulnerabilities":[{"id":"CVE-2023-7008","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"urls":["https://access.redhat.com/errata/RHSA-2024:2463","https://access.redhat.com/errata/RHSA-2024:3203","https://access.redhat.com/security/cve/CVE-2023-7008","https://bugzilla.redhat.com/show_bug.cgi?id=2222261","https://bugzilla.redhat.com/show_bug.cgi?id=2222672","https://github.com/systemd/systemd/issues/25676","https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/","https://security.netapp.com/advisory/ntap-20241122-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-7008","description":"A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-7008","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-7008","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"risk":0.2547,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-7008"},"relatedVulnerabilities":[{"id":"CVE-2023-7008","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"urls":["https://access.redhat.com/errata/RHSA-2024:2463","https://access.redhat.com/errata/RHSA-2024:3203","https://access.redhat.com/security/cve/CVE-2023-7008","https://bugzilla.redhat.com/show_bug.cgi?id=2222261","https://bugzilla.redhat.com/show_bug.cgi?id=2222672","https://github.com/systemd/systemd/issues/25676","https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/","https://security.netapp.com/advisory/ntap-20241122-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-7008","description":"A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-7008","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-7008","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"risk":0.2547,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-7008"},"relatedVulnerabilities":[{"id":"CVE-2023-7008","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-7008","cwe":"CWE-300","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-7008","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-7008","date":"2026-10-05","epss":0.00849,"percentile":0.56685}],"urls":["https://access.redhat.com/errata/RHSA-2024:2463","https://access.redhat.com/errata/RHSA-2024:3203","https://access.redhat.com/security/cve/CVE-2023-7008","https://bugzilla.redhat.com/show_bug.cgi?id=2222261","https://bugzilla.redhat.com/show_bug.cgi?id=2222672","https://github.com/systemd/systemd/issues/25676","https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL/","https://security.netapp.com/advisory/ntap-20241122-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-7008","description":"A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-40909","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-40909","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-40909","cwe":"CWE-426","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2025-40909","cwe":"CWE-689","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-40909","date":"2026-10-05","epss":0.00504,"percentile":0.4095}],"risk":0.252,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-40909"},"relatedVulnerabilities":[{"id":"CVE-2025-40909","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"impactScore":3.4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-40909","cwe":"CWE-426","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2025-40909","cwe":"CWE-689","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-40909","date":"2026-10-05","epss":0.00504,"percentile":0.4095}],"urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098226","https://github.com/Perl/perl5/commit/11a11ecf4bea72b17d250cfb43c897be1341861e","https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9.patch","https://github.com/Perl/perl5/issues/10387","https://github.com/Perl/perl5/issues/23010","https://perldoc.perl.org/5.14.0/perl5136delta#Directory-handles-not-copied-to-threads","https://www.openwall.com/lists/oss-security/2025/05/22/2","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/54","http://seclists.org/fulldisclosure/2025/Sep/55","http://www.openwall.com/lists/oss-security/2025/05/23/1","http://www.openwall.com/lists/oss-security/2025/05/30/4","http://www.openwall.com/lists/oss-security/2025/06/02/2","http://www.openwall.com/lists/oss-security/2025/06/02/5","http://www.openwall.com/lists/oss-security/2025/06/02/6","http://www.openwall.com/lists/oss-security/2025/06/02/7","http://www.openwall.com/lists/oss-security/2025/06/03/1","https://lists.debian.org/debian-lts-announce/2026/04/msg00018.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40909","description":"Perl threads have a working directory race condition where file operations may target unintended paths.\n\nIf a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. \n\nThis may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.\n\nThe bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6"}]},{"artifact":{"id":"72ed83bf5ce56df5","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"76d2edbbdcb350bc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"a55791055d3bc034","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.1.8-3.1ubuntu3?arch=all&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"0865b93c3edcb069","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-05","epss":0.005,"percentile":0.40687}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"risk":0.24949999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15281"},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"risk":0.24949999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15281"},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"risk":0.24949999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15281"},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-05","epss":0.00499,"percentile":0.40591}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-05","epss":0.00495,"percentile":0.40379}],"risk":0.24750000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48962"},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-05","epss":0.00495,"percentile":0.40379}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5928"},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5928"},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5928"},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-05","epss":0.00493,"percentile":0.40212}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-45582","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-45582","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-05","epss":0.00489,"percentile":0.39921}],"risk":0.24450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-45582"},"relatedVulnerabilities":[{"id":"CVE-2025-45582","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":2.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-05","epss":0.00489,"percentile":0.39921}],"urls":["https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md","https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html","https://www.gnu.org/software/tar/","https://www.gnu.org/software/tar/manual/html_node/Integrity.html","https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html","http://www.openwall.com/lists/oss-security/2025/11/01/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-45582","description":"GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10684","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10684","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"risk":0.24380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10684"},"relatedVulnerabilities":[{"id":"CVE-2017-10684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464687","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10684","description":"In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10684","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10684","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"risk":0.24380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10684"},"relatedVulnerabilities":[{"id":"CVE-2017-10684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464687","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10684","description":"In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10684","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10684","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"risk":0.24380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10684"},"relatedVulnerabilities":[{"id":"CVE-2017-10684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464687","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10684","description":"In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10684","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10684","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"risk":0.24380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10684"},"relatedVulnerabilities":[{"id":"CVE-2017-10684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464687","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10684","description":"In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10684","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10684","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"risk":0.24380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10684"},"relatedVulnerabilities":[{"id":"CVE-2017-10684","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10684","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10684","date":"2026-10-05","epss":0.04876,"percentile":0.91799}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464687","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10684","description":"In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.22.1-9ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6185","versionConstraint":"< 5.22.1-9ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6185","fix":{"state":"fixed","versions":["5.22.1-9ubuntu0.3"],"available":[{"date":"2018-04-16","kind":"advisory","version":"5.22.1-9ubuntu0.3"}]},"cvss":[],"epss":[{"cve":"CVE-2016-6185","date":"2026-10-05","epss":0.00787,"percentile":0.5464}],"risk":0.23609999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6185"},"relatedVulnerabilities":[{"id":"CVE-2016-6185","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-6185","date":"2026-10-05","epss":0.00787,"percentile":0.5464}],"urls":["http://perl5.git.perl.org/perl.git/commitdiff/08e3451d7","http://www.debian.org/security/2016/dsa-3628","http://www.openwall.com/lists/oss-security/2016/07/07/1","http://www.openwall.com/lists/oss-security/2016/07/08/5","http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html","http://www.securityfocus.com/bid/91685","http://www.securitytracker.com/id/1036260","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5RFDMASVZLFZYBB2GNTZXU6I76E4NA4V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITYZJXQH24X2F2LAOQEQAC5KXLYJTJ76/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PRIPTDA6XINBVEJXI2NGLKVEINBREHTN/","https://rt.cpan.org/Public/Bug/Display.html?id=115808","https://security.gentoo.org/glsa/201701-75","https://usn.ubuntu.com/3625-1/","https://usn.ubuntu.com/3625-2/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6185","description":"The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-05","epss":0.00471,"percentile":0.3853}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42497"},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-05","epss":0.00471,"percentile":0.3853}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"72ed83bf5ce56df5","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6020","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-6020","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6020"},"relatedVulnerabilities":[{"id":"CVE-2025-6020","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"urls":["https://access.redhat.com/errata/RHSA-2025:10024","https://access.redhat.com/errata/RHSA-2025:10027","https://access.redhat.com/errata/RHSA-2025:10180","https://access.redhat.com/errata/RHSA-2025:10354","https://access.redhat.com/errata/RHSA-2025:10357","https://access.redhat.com/errata/RHSA-2025:10358","https://access.redhat.com/errata/RHSA-2025:10359","https://access.redhat.com/errata/RHSA-2025:10361","https://access.redhat.com/errata/RHSA-2025:10362","https://access.redhat.com/errata/RHSA-2025:10735","https://access.redhat.com/errata/RHSA-2025:10823","https://access.redhat.com/errata/RHSA-2025:11386","https://access.redhat.com/errata/RHSA-2025:11487","https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:20181","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:22019","https://access.redhat.com/errata/RHSA-2025:9526","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/security/cve/CVE-2025-6020","https://bugzilla.redhat.com/show_bug.cgi?id=2372512","https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx","http://www.openwall.com/lists/oss-security/2025/06/17/1","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."}]},{"artifact":{"id":"76d2edbbdcb350bc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6020","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-6020","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6020"},"relatedVulnerabilities":[{"id":"CVE-2025-6020","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"urls":["https://access.redhat.com/errata/RHSA-2025:10024","https://access.redhat.com/errata/RHSA-2025:10027","https://access.redhat.com/errata/RHSA-2025:10180","https://access.redhat.com/errata/RHSA-2025:10354","https://access.redhat.com/errata/RHSA-2025:10357","https://access.redhat.com/errata/RHSA-2025:10358","https://access.redhat.com/errata/RHSA-2025:10359","https://access.redhat.com/errata/RHSA-2025:10361","https://access.redhat.com/errata/RHSA-2025:10362","https://access.redhat.com/errata/RHSA-2025:10735","https://access.redhat.com/errata/RHSA-2025:10823","https://access.redhat.com/errata/RHSA-2025:11386","https://access.redhat.com/errata/RHSA-2025:11487","https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:20181","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:22019","https://access.redhat.com/errata/RHSA-2025:9526","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/security/cve/CVE-2025-6020","https://bugzilla.redhat.com/show_bug.cgi?id=2372512","https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx","http://www.openwall.com/lists/oss-security/2025/06/17/1","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."}]},{"artifact":{"id":"a55791055d3bc034","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.1.8-3.1ubuntu3?arch=all&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6020","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-6020","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6020"},"relatedVulnerabilities":[{"id":"CVE-2025-6020","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"urls":["https://access.redhat.com/errata/RHSA-2025:10024","https://access.redhat.com/errata/RHSA-2025:10027","https://access.redhat.com/errata/RHSA-2025:10180","https://access.redhat.com/errata/RHSA-2025:10354","https://access.redhat.com/errata/RHSA-2025:10357","https://access.redhat.com/errata/RHSA-2025:10358","https://access.redhat.com/errata/RHSA-2025:10359","https://access.redhat.com/errata/RHSA-2025:10361","https://access.redhat.com/errata/RHSA-2025:10362","https://access.redhat.com/errata/RHSA-2025:10735","https://access.redhat.com/errata/RHSA-2025:10823","https://access.redhat.com/errata/RHSA-2025:11386","https://access.redhat.com/errata/RHSA-2025:11487","https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:20181","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:22019","https://access.redhat.com/errata/RHSA-2025:9526","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/security/cve/CVE-2025-6020","https://bugzilla.redhat.com/show_bug.cgi?id=2372512","https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx","http://www.openwall.com/lists/oss-security/2025/06/17/1","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."}]},{"artifact":{"id":"0865b93c3edcb069","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6020","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-6020","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6020"},"relatedVulnerabilities":[{"id":"CVE-2025-6020","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-05","epss":0.0046,"percentile":0.37733}],"urls":["https://access.redhat.com/errata/RHSA-2025:10024","https://access.redhat.com/errata/RHSA-2025:10027","https://access.redhat.com/errata/RHSA-2025:10180","https://access.redhat.com/errata/RHSA-2025:10354","https://access.redhat.com/errata/RHSA-2025:10357","https://access.redhat.com/errata/RHSA-2025:10358","https://access.redhat.com/errata/RHSA-2025:10359","https://access.redhat.com/errata/RHSA-2025:10361","https://access.redhat.com/errata/RHSA-2025:10362","https://access.redhat.com/errata/RHSA-2025:10735","https://access.redhat.com/errata/RHSA-2025:10823","https://access.redhat.com/errata/RHSA-2025:11386","https://access.redhat.com/errata/RHSA-2025:11487","https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:20181","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:22019","https://access.redhat.com/errata/RHSA-2025:9526","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/security/cve/CVE-2025-6020","https://bugzilla.redhat.com/show_bug.cgi?id=2372512","https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx","http://www.openwall.com/lists/oss-security/2025/06/17/1","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."}]},{"artifact":{"id":"72ed83bf5ce56df5","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-22365","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-22365","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"risk":0.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-22365"},"relatedVulnerabilities":[{"id":"CVE-2024-22365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"urls":["http://www.openwall.com/lists/oss-security/2024/01/18/3","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb","https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22365","description":"linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY."}]},{"artifact":{"id":"76d2edbbdcb350bc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-22365","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-22365","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"risk":0.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-22365"},"relatedVulnerabilities":[{"id":"CVE-2024-22365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"urls":["http://www.openwall.com/lists/oss-security/2024/01/18/3","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb","https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22365","description":"linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY."}]},{"artifact":{"id":"a55791055d3bc034","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.1.8-3.1ubuntu3?arch=all&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-22365","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-22365","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"risk":0.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-22365"},"relatedVulnerabilities":[{"id":"CVE-2024-22365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"urls":["http://www.openwall.com/lists/oss-security/2024/01/18/3","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb","https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22365","description":"linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY."}]},{"artifact":{"id":"0865b93c3edcb069","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.1.8-3.1ubuntu3:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.1.8-3.1ubuntu3?arch=amd64&distro=ubuntu-16.04&upstream=pam","type":"deb","version":"1.1.8-3.1ubuntu3","language":"","licenses":["sha256:7c584b7b1f37b612da7fdf3b076eb2b2c1bae72865f0699d745ae2ac7d40d13e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-22365","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pam","version":"1.1.8-3.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-22365","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"risk":0.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-22365"},"relatedVulnerabilities":[{"id":"CVE-2024-22365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22365","cwe":"CWE-664","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22365","date":"2026-10-05","epss":0.00459,"percentile":0.37574}],"urls":["http://www.openwall.com/lists/oss-security/2024/01/18/3","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb","https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22365","description":"linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY."}]},{"artifact":{"id":"2916ecd7c14c26b2","cpes":["cpe:2.3:a:gcc-5-base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5-base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"gcc-5-base","purl":"pkg:deb/ubuntu/gcc-5-base@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gcc-5-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4039","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4039","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4039"},"relatedVulnerabilities":[{"id":"CVE-2023-4039","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"arm-security@arm.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"urls":["https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64","https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4039","description":"**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself."}]},{"artifact":{"id":"ea776ff124db708b","cpes":["cpe:2.3:a:libgcc1:libgcc1:1\\:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libgcc1","purl":"pkg:deb/ubuntu/libgcc1@1%3A5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5%405.3.1-7ubuntu1","type":"deb","version":"1:5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcc1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5","version":"5.3.1-7ubuntu1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4039","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4039","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4039"},"relatedVulnerabilities":[{"id":"CVE-2023-4039","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"arm-security@arm.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"urls":["https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64","https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4039","description":"**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself."}]},{"artifact":{"id":"ef656887b7b17615","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/ubuntu/libstdc%2B%2B6@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4039","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2023-4039","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-4039"},"relatedVulnerabilities":[{"id":"CVE-2023-4039","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"arm-security@arm.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4039","cwe":"CWE-693","type":"Secondary","source":"arm-security@arm.com"},{"cve":"CVE-2023-4039","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4039","date":"2026-10-05","epss":0.00764,"percentile":0.53874}],"urls":["https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64","https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-x7ch-h5rf-w2mf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4039","description":"**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains \nthat target AArch64 allows an attacker to exploit an existing buffer \noverflow in dynamically-sized local variables in your application \nwithout this being detected. This stack-protector failure only applies \nto C99-style dynamically-sized local variables or those created using \nalloca(). The stack-protector operates as intended for statically-sized \nlocal variables.\n\nThe default behavior when the stack-protector \ndetects an overflow is to terminate your application, resulting in \ncontrolled loss of availability. An attacker who can exploit a buffer \noverflow without triggering the stack-protector might be able to change \nprogram flow control to cause an uncontrolled loss of availability or to\n go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10029","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-10029","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10029"},"relatedVulnerabilities":[{"id":"CVE-2020-10029","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/23N76M3EDP2GIW4GOIQRYTKRE7PPBRB2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTFUD5VH2GU3YOXA2KBQSBIDZRDWNZ3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU5JJGENOK7K4X5RYAA5PL647C6HD22E/","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200327-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=25487","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=9333498794cde1d5cca518badf79533a24114b6f","https://usn.ubuntu.com/4416-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10029","description":"The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10029","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-10029","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10029"},"relatedVulnerabilities":[{"id":"CVE-2020-10029","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/23N76M3EDP2GIW4GOIQRYTKRE7PPBRB2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTFUD5VH2GU3YOXA2KBQSBIDZRDWNZ3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU5JJGENOK7K4X5RYAA5PL647C6HD22E/","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200327-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=25487","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=9333498794cde1d5cca518badf79533a24114b6f","https://usn.ubuntu.com/4416-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10029","description":"The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10029","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-10029","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"risk":0.2292,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10029"},"relatedVulnerabilities":[{"id":"CVE-2020-10029","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10029","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10029","date":"2026-10-05","epss":0.00764,"percentile":0.5386}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/23N76M3EDP2GIW4GOIQRYTKRE7PPBRB2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTFUD5VH2GU3YOXA2KBQSBIDZRDWNZ3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU5JJGENOK7K4X5RYAA5PL647C6HD22E/","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20200327-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=25487","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=9333498794cde1d5cca518badf79533a24114b6f","https://usn.ubuntu.com/4416-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10029","description":"The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.27"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1712","versionConstraint":"< 229-4ubuntu21.27 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1712","fix":{"state":"fixed","versions":["229-4ubuntu21.27"],"available":[{"date":"2020-02-05","kind":"advisory","version":"229-4ubuntu21.27"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"risk":0.22799999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1712"},"relatedVulnerabilities":[{"id":"CVE-2020-1712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712","https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54","https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","https://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2d","https://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2","https://lists.debian.org/debian-lts-announce/2022/06/msg00025.html","https://www.openwall.com/lists/oss-security/2020/02/05/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1712","description":"A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.27"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1712","versionConstraint":"< 229-4ubuntu21.27 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1712","fix":{"state":"fixed","versions":["229-4ubuntu21.27"],"available":[{"date":"2020-02-05","kind":"advisory","version":"229-4ubuntu21.27"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"risk":0.22799999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1712"},"relatedVulnerabilities":[{"id":"CVE-2020-1712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712","https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54","https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","https://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2d","https://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2","https://lists.debian.org/debian-lts-announce/2022/06/msg00025.html","https://www.openwall.com/lists/oss-security/2020/02/05/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1712","description":"A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.27"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-1712","versionConstraint":"< 229-4ubuntu21.27 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1712","fix":{"state":"fixed","versions":["229-4ubuntu21.27"],"available":[{"date":"2020-02-05","kind":"advisory","version":"229-4ubuntu21.27"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"risk":0.22799999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1712"},"relatedVulnerabilities":[{"id":"CVE-2020-1712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712","https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54","https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","https://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2d","https://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2","https://lists.debian.org/debian-lts-announce/2022/06/msg00025.html","https://www.openwall.com/lists/oss-security/2020/02/05/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1712","description":"A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"229-4ubuntu21.27"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1712","versionConstraint":"< 229-4ubuntu21.27 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1712","fix":{"state":"fixed","versions":["229-4ubuntu21.27"],"available":[{"date":"2020-02-05","kind":"advisory","version":"229-4ubuntu21.27"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"risk":0.22799999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1712"},"relatedVulnerabilities":[{"id":"CVE-2020-1712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1712","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1712","date":"2026-10-05","epss":0.00456,"percentile":0.37376}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712","https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54","https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","https://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2d","https://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2","https://lists.debian.org/debian-lts-announce/2022/06/msg00025.html","https://www.openwall.com/lists/oss-security/2020/02/05/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1712","description":"A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-05","epss":0.00448,"percentile":0.36776}],"risk":0.22399999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-9538"},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-05","epss":0.00448,"percentile":0.36776}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"risk":0.22200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6238"},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"risk":0.22200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6238"},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"risk":0.22200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6238"},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-05","epss":0.00444,"percentile":0.36358}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-05","epss":0.00432,"percentile":0.35333}],"risk":0.216,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13221"},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-05","epss":0.00432,"percentile":0.35333}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10685","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"risk":0.21284999999999998,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10685"},"relatedVulnerabilities":[{"id":"CVE-2017-10685","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464692","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10685","description":"In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10685","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"risk":0.21284999999999998,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10685"},"relatedVulnerabilities":[{"id":"CVE-2017-10685","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464692","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10685","description":"In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10685","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"risk":0.21284999999999998,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10685"},"relatedVulnerabilities":[{"id":"CVE-2017-10685","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464692","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10685","description":"In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10685","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"risk":0.21284999999999998,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10685"},"relatedVulnerabilities":[{"id":"CVE-2017-10685","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464692","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10685","description":"In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-10685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-10685","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"risk":0.21284999999999998,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-10685"},"relatedVulnerabilities":[{"id":"CVE-2017-10685","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-10685","cwe":"CWE-134","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-10685","date":"2026-10-05","epss":0.04257,"percentile":0.9077}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1464692","https://security.gentoo.org/glsa/201804-13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-10685","description":"In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack."}]},{"artifact":{"id":"394b20adad2b551a","cpes":["cpe:2.3:a:libcryptsetup4:libcryptsetup4:2\\:1.6.6-5ubuntu2:*:*:*:*:*:*:*"],"name":"libcryptsetup4","purl":"pkg:deb/ubuntu/libcryptsetup4@2%3A1.6.6-5ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=cryptsetup","type":"deb","version":"2:1.6.6-5ubuntu2","language":"","licenses":["GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcryptsetup4/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libcryptsetup4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcryptsetup4:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libcryptsetup4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cryptsetup"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-4484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"cryptsetup","version":"2:1.6.6-5ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-4484","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-4484","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4484","date":"2026-10-05","epss":0.00709,"percentile":0.51886}],"risk":0.2127,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-4484"},"relatedVulnerabilities":[{"id":"CVE-2016-4484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.8,"impactScore":5.9,"exploitabilityScore":1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-4484","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-4484","date":"2026-10-05","epss":0.00709,"percentile":0.51886}],"urls":["http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html","http://www.openwall.com/lists/oss-security/2016/11/14/13","http://www.openwall.com/lists/oss-security/2016/11/15/1","http://www.openwall.com/lists/oss-security/2016/11/15/4","http://www.openwall.com/lists/oss-security/2016/11/16/6","http://www.securityfocus.com/bid/94315","https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-4484","description":"The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password."}]},{"artifact":{"id":"70c57114e8f82a71","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3821","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-3821","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"risk":0.21,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3821"},"relatedVulnerabilities":[{"id":"CVE-2022-3821","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2139327","https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e","https://github.com/systemd/systemd/issues/23928","https://github.com/systemd/systemd/pull/23933","https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/","https://security.gentoo.org/glsa/202305-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3821","description":"An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service."}]},{"artifact":{"id":"7032906d49d9f8bb","cpes":["cpe:2.3:a:libudev1:libudev1:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3821","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-3821","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"risk":0.21,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3821"},"relatedVulnerabilities":[{"id":"CVE-2022-3821","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2139327","https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e","https://github.com/systemd/systemd/issues/23928","https://github.com/systemd/systemd/pull/23933","https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/","https://security.gentoo.org/glsa/202305-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3821","description":"An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service."}]},{"artifact":{"id":"31d8da6c51f78ef0","cpes":["cpe:2.3:a:systemd:systemd:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/ubuntu/systemd@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-3821","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-3821","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"risk":0.21,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3821"},"relatedVulnerabilities":[{"id":"CVE-2022-3821","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2139327","https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e","https://github.com/systemd/systemd/issues/23928","https://github.com/systemd/systemd/pull/23933","https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/","https://security.gentoo.org/glsa/202305-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3821","description":"An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service."}]},{"artifact":{"id":"93e1f9222f0999e6","cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:228-4ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:228-4ubuntu1:*:*:*:*:*:*:*"],"name":"systemd-sysv","purl":"pkg:deb/ubuntu/systemd-sysv@228-4ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=systemd","type":"deb","version":"228-4ubuntu1","language":"","licenses":["CC0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3821","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"systemd","version":"228-4ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2022-3821","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"risk":0.21,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3821"},"relatedVulnerabilities":[{"id":"CVE-2022-3821","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3821","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3821","date":"2026-10-05","epss":0.0042,"percentile":0.34132}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2139327","https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e","https://github.com/systemd/systemd/issues/23928","https://github.com/systemd/systemd/pull/23933","https://lists.debian.org/debian-lts-announce/2023/06/msg00036.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/","https://security.gentoo.org/glsa/202305-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3821","description":"An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service."}]},{"artifact":{"id":"42899f1499942b30","cpes":["cpe:2.3:a:libpcre3:libpcre3:2\\:8.38-1ubuntu1:*:*:*:*:*:*:*"],"name":"libpcre3","purl":"pkg:deb/ubuntu/libpcre3@2%3A8.38-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=pcre3","type":"deb","version":"2:8.38-1ubuntu1","language":"","licenses":["sha256:ac9276490d2fa167442ae1aae33926514ad10c8886baa40046c5e367fccc5938"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpcre3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14155","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pcre3","version":"2:8.38-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-14155","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-14155","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14155","date":"2026-10-05","epss":0.04182,"percentile":0.90625}],"risk":0.20910000000000004,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14155"},"relatedVulnerabilities":[{"id":"CVE-2020-14155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14155","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14155","date":"2026-10-05","epss":0.04182,"percentile":0.90625}],"urls":["http://seclists.org/fulldisclosure/2020/Dec/32","http://seclists.org/fulldisclosure/2021/Feb/14","https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/","https://bugs.gentoo.org/717920","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://security.netapp.com/advisory/ntap-20221028-0010/","https://support.apple.com/kb/HT211931","https://support.apple.com/kb/HT212147","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.pcre.org/original/changelog.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14155","description":"libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-05","epss":0.00418,"percentile":0.33905}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19487"},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-05","epss":0.00418,"percentile":0.33905}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80489"},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80489"},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80489"},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-05","epss":0.00412,"percentile":0.33205}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77117"},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77117"},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77117"},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-05","epss":0.00412,"percentile":0.33202}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"d14be6bc8e5294e4","cpes":["cpe:2.3:a:login:login:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/login.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:4.2-3.1ubuntu5.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6252","versionConstraint":"< 1:4.2-3.1ubuntu5.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6252","fix":{"state":"fixed","versions":["1:4.2-3.1ubuntu5.2"],"available":[{"date":"2017-05-05","kind":"advisory","version":"1:4.2-3.1ubuntu5.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6252","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6252","date":"2026-10-05","epss":0.00409,"percentile":0.32844}],"risk":0.2045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6252"},"relatedVulnerabilities":[{"id":"CVE-2016-6252","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6252","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6252","date":"2026-10-05","epss":0.00409,"percentile":0.32844}],"urls":["http://www.debian.org/security/2017/dsa-3793","http://www.openwall.com/lists/oss-security/2016/07/19/6","http://www.openwall.com/lists/oss-security/2016/07/19/7","http://www.openwall.com/lists/oss-security/2016/07/20/2","http://www.openwall.com/lists/oss-security/2016/07/25/7","http://www.securityfocus.com/bid/92055","https://bugzilla.suse.com/show_bug.cgi?id=979282","https://github.com/shadow-maint/shadow/issues/27","https://security.gentoo.org/glsa/201706-02"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6252","description":"Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap."}]},{"artifact":{"id":"f0c7bab4ad17922b","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.1.5.1-1.1ubuntu7:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.1.5.1-1.1ubuntu7?arch=amd64&distro=ubuntu-16.04&upstream=shadow","type":"deb","version":"1:4.1.5.1-1.1ubuntu7","language":"","licenses":["sha256:25978a8d70ddb4c897fd2b817c0d692c19ab81884944153669545bbc3d67f0ee"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/passwd.preinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:4.2-3.1ubuntu5.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-6252","versionConstraint":"< 1:4.2-3.1ubuntu5.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"shadow","version":"1:4.1.5.1-1.1ubuntu7"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-6252","fix":{"state":"fixed","versions":["1:4.2-3.1ubuntu5.2"],"available":[{"date":"2017-05-05","kind":"advisory","version":"1:4.2-3.1ubuntu5.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2016-6252","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6252","date":"2026-10-05","epss":0.00409,"percentile":0.32844}],"risk":0.2045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-6252"},"relatedVulnerabilities":[{"id":"CVE-2016-6252","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-6252","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-6252","date":"2026-10-05","epss":0.00409,"percentile":0.32844}],"urls":["http://www.debian.org/security/2017/dsa-3793","http://www.openwall.com/lists/oss-security/2016/07/19/6","http://www.openwall.com/lists/oss-security/2016/07/19/7","http://www.openwall.com/lists/oss-security/2016/07/20/2","http://www.openwall.com/lists/oss-security/2016/07/25/7","http://www.securityfocus.com/bid/92055","https://bugzilla.suse.com/show_bug.cgi?id=979282","https://github.com/shadow-maint/shadow/issues/27","https://security.gentoo.org/glsa/201706-02"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-6252","description":"Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-05","epss":0.00407,"percentile":0.32688}],"risk":0.2035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48961"},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-05","epss":0.00407,"percentile":0.32688}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33602","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33602","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33602"},"relatedVulnerabilities":[{"id":"CVE-2024-33602","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0012/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33602","description":"nscd: netgroup cache assumes NSS callback uses in-buffer strings\n\nThe Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory\nwhen the NSS callback does not store all strings in the provided buffer.\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33602","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33602","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33602"},"relatedVulnerabilities":[{"id":"CVE-2024-33602","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0012/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33602","description":"nscd: netgroup cache assumes NSS callback uses in-buffer strings\n\nThe Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory\nwhen the NSS callback does not store all strings in the provided buffer.\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-33602","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2024-33602","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-33602"},"relatedVulnerabilities":[{"id":"CVE-2024-33602","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-33602","cwe":"CWE-466","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-33602","date":"2026-10-05","epss":0.00403,"percentile":0.32244}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html","https://security.netapp.com/advisory/ntap-20240524-0012/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-33602","description":"nscd: netgroup cache assumes NSS callback uses in-buffer strings\n\nThe Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory\nwhen the NSS callback does not store all strings in the provided buffer.\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-05","epss":0.00401,"percentile":0.32041}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5704"},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-05","epss":0.00401,"percentile":0.32041}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-10228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-10228","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"risk":0.2003,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-10228"},"relatedVulnerabilities":[{"id":"CVE-2016-10228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"urls":["http://openwall.com/lists/oss-security/2017/03/01/10","http://www.securityfocus.com/bid/96525","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=19519","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10228","description":"The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-10228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-10228","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"risk":0.2003,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-10228"},"relatedVulnerabilities":[{"id":"CVE-2016-10228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"urls":["http://openwall.com/lists/oss-security/2017/03/01/10","http://www.securityfocus.com/bid/96525","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=19519","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10228","description":"The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-10228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2016-10228","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"risk":0.2003,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-10228"},"relatedVulnerabilities":[{"id":"CVE-2016-10228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-10228","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10228","date":"2026-10-05","epss":0.04006,"percentile":0.90247}],"urls":["http://openwall.com/lists/oss-security/2017/03/01/10","http://www.securityfocus.com/bid/96525","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=19519","https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21","https://sourceware.org/bugzilla/show_bug.cgi?id=26224","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10228","description":"The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5435"},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5435"},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5435"},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-05","epss":0.00394,"percentile":0.31292}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-5155","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2009-5155","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"risk":0.19529999999999997,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2009-5155"},"relatedVulnerabilities":[{"id":"CVE-2009-5155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"urls":["http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=11053","https://sourceware.org/bugzilla/show_bug.cgi?id=18986","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672","https://support.f5.com/csp/article/K64119434","https://support.f5.com/csp/article/K64119434?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-5155","description":"In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-5155","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2009-5155","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"risk":0.19529999999999997,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2009-5155"},"relatedVulnerabilities":[{"id":"CVE-2009-5155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"urls":["http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=11053","https://sourceware.org/bugzilla/show_bug.cgi?id=18986","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672","https://support.f5.com/csp/article/K64119434","https://support.f5.com/csp/article/K64119434?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-5155","description":"In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2009-5155","versionConstraint":"< 2.23-0ubuntu11.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2009-5155","fix":{"state":"fixed","versions":["2.23-0ubuntu11.3"],"available":[{"date":"2021-05-14","kind":"advisory","version":"2.23-0ubuntu11.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"risk":0.19529999999999997,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2009-5155"},"relatedVulnerabilities":[{"id":"CVE-2009-5155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2009-5155","cwe":"CWE-19","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2009-5155","date":"2026-10-05","epss":0.03906,"percentile":0.89974}],"urls":["http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=11053","https://sourceware.org/bugzilla/show_bug.cgi?id=18986","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=eb04c21373e2a2885f3d52ff192b0499afe3c672","https://support.f5.com/csp/article/K64119434","https://support.f5.com/csp/article/K64119434?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2009-5155","description":"In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13728","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13728","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"risk":0.1948,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13728"},"relatedVulnerabilities":[{"id":"CVE-2017-13728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484274","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13728","description":"There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13728","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13728","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"risk":0.1948,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13728"},"relatedVulnerabilities":[{"id":"CVE-2017-13728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484274","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13728","description":"There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13728","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13728","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"risk":0.1948,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13728"},"relatedVulnerabilities":[{"id":"CVE-2017-13728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484274","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13728","description":"There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13728","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13728","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"risk":0.1948,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13728"},"relatedVulnerabilities":[{"id":"CVE-2017-13728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484274","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13728","description":"There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13728","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13728","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"risk":0.1948,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13728"},"relatedVulnerabilities":[{"id":"CVE-2017-13728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13728","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13728","date":"2026-10-05","epss":0.03896,"percentile":0.89946}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484274","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13728","description":"There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack."}]},{"artifact":{"id":"09f678f8187b6d3f","cpes":["cpe:2.3:a:apt:apt:1.1.10:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/ubuntu/apt@1.1.10?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.32ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-27350","versionConstraint":"< 1.2.32ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-27350","fix":{"state":"fixed","versions":["1.2.32ubuntu0.2"],"available":[{"date":"2020-12-09","kind":"advisory","version":"1.2.32ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-27350","date":"2026-10-05","epss":0.00378,"percentile":0.29458}],"risk":0.189,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27350"},"relatedVulnerabilities":[{"id":"CVE-2020-27350","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.7,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.7,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-27350","date":"2026-10-05","epss":0.00378,"percentile":0.29458}],"urls":["https://bugs.launchpad.net/bugs/1899193","https://security.netapp.com/advisory/ntap-20210108-0005/","https://usn.ubuntu.com/usn/usn-4667-1","https://www.debian.org/security/2020/dsa-4808"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27350","description":"APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;"}]},{"artifact":{"id":"aba0f26b4d9c7fe4","cpes":["cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg5.0:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg5.0:1.1.10:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg5.0:1.1.10:*:*:*:*:*:*:*"],"name":"libapt-pkg5.0","purl":"pkg:deb/ubuntu/libapt-pkg5.0@1.1.10?arch=amd64&distro=ubuntu-16.04&upstream=apt","type":"deb","version":"1.1.10","language":"","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg5.0/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libapt-pkg5.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libapt-pkg5.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.2.32ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27350","versionConstraint":"< 1.2.32ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"apt","version":"1.1.10"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-27350","fix":{"state":"fixed","versions":["1.2.32ubuntu0.2"],"available":[{"date":"2020-12-09","kind":"advisory","version":"1.2.32ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-27350","date":"2026-10-05","epss":0.00378,"percentile":0.29458}],"risk":0.189,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27350"},"relatedVulnerabilities":[{"id":"CVE-2020-27350","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.7,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.7,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2020-27350","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-27350","date":"2026-10-05","epss":0.00378,"percentile":0.29458}],"urls":["https://bugs.launchpad.net/bugs/1899193","https://security.netapp.com/advisory/ntap-20210108-0005/","https://usn.ubuntu.com/usn/usn-4667-1","https://www.debian.org/security/2020/dsa-4808"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27350","description":"APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;"}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-05","epss":0.00374,"percentile":0.29071}],"risk":0.187,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12087"},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-05","epss":0.00374,"percentile":0.29071}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"2916ecd7c14c26b2","cpes":["cpe:2.3:a:gcc-5-base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5-base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5_base:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_5:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-5-base:5.3.1-7ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_5_base:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"gcc-5-base","purl":"pkg:deb/ubuntu/gcc-5-base@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/gcc-5-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/gcc-5-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"risk":0.1815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95619"},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ea776ff124db708b","cpes":["cpe:2.3:a:libgcc1:libgcc1:1\\:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libgcc1","purl":"pkg:deb/ubuntu/libgcc1@1%3A5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5%405.3.1-7ubuntu1","type":"deb","version":"1:5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libgcc1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libgcc1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5","version":"5.3.1-7ubuntu1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"risk":0.1815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95619"},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ef656887b7b17615","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:5.3.1-7ubuntu1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/ubuntu/libstdc%2B%2B6@5.3.1-7ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=gcc-5","type":"deb","version":"5.3.1-7ubuntu1","language":"","licenses":["sha256:2e95084462ca25abe8d6a85bd821804d77d3576b37f2658977f302e15de40362"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-5-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"gcc-5","version":"5.3.1-7ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"risk":0.1815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95619"},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-05","epss":0.00363,"percentile":0.279}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"5f403701baf2edcc","cpes":["cpe:2.3:a:perl-base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.22.1-4:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.22.1-4:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.22.1-4?arch=amd64&distro=ubuntu-16.04&upstream=perl","type":"deb","version":"5.22.1-4","language":"","licenses":["Artistic","Artistic-2","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"perl","version":"5.22.1-4"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-05","epss":0.00357,"percentile":0.27161}],"risk":0.1785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57433"},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-05","epss":0.00357,"percentile":0.27161}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0395","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-0395","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-0395"},"relatedVulnerabilities":[{"id":"CVE-2025-0395","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32582","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001","https://sourceware.org/pipermail/libc-announce/2025/000044.html","https://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/23/2","http://www.openwall.com/lists/oss-security/2025/04/13/1","http://www.openwall.com/lists/oss-security/2025/04/24/7","https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html","https://security.netapp.com/advisory/ntap-20250228-0006/","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7971add7ee4171fdd8dfd17e7c04c4ed77a18845","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0395","description":"When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0395","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-0395","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-0395"},"relatedVulnerabilities":[{"id":"CVE-2025-0395","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32582","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001","https://sourceware.org/pipermail/libc-announce/2025/000044.html","https://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/23/2","http://www.openwall.com/lists/oss-security/2025/04/13/1","http://www.openwall.com/lists/oss-security/2025/04/24/7","https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html","https://security.netapp.com/advisory/ntap-20250228-0006/","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7971add7ee4171fdd8dfd17e7c04c4ed77a18845","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0395","description":"When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0395","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2025-0395","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-0395"},"relatedVulnerabilities":[{"id":"CVE-2025-0395","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0395","cwe":"CWE-131","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-0395","date":"2026-10-05","epss":0.00356,"percentile":0.27063}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32582","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001","https://sourceware.org/pipermail/libc-announce/2025/000044.html","https://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/22/4","http://www.openwall.com/lists/oss-security/2025/01/23/2","http://www.openwall.com/lists/oss-security/2025/04/13/1","http://www.openwall.com/lists/oss-security/2025/04/24/7","https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html","https://security.netapp.com/advisory/ntap-20250228-0006/","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7971add7ee4171fdd8dfd17e7c04c4ed77a18845","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0395","description":"When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size."}]},{"artifact":{"id":"309730a113abcdf8","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.1.1alpha\\+20120614-2ubuntu2:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/ubuntu/liblzma5@5.1.1alpha%2B20120614-2ubuntu2?arch=amd64&distro=ubuntu-16.04&upstream=xz-utils","type":"deb","version":"5.1.1alpha+20120614-2ubuntu2","language":"","licenses":["Autoconf","GPL-2","GPL-2+","GPL-3","LGPL-2","LGPL-2.1","LGPL-2.1+","PD","PD-debian","config-h","noderivs","permissive-fsf","permissive-nowarranty","probably-PD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblzma5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/liblzma5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"xz-utils","version":"5.1.1alpha+20120614-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-05","epss":0.00573,"percentile":0.45399}],"risk":0.17189999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34743"},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-05","epss":0.00573,"percentile":0.45399}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-05","epss":0.00342,"percentile":0.25408}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a01bcd397809c1de","cpes":["cpe:2.3:a:diffutils:diffutils:1\\:3.3-3:*:*:*:*:*:*:*"],"name":"diffutils","purl":"pkg:deb/ubuntu/diffutils@1%3A3.3-3?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1:3.3-3","language":"","licenses":["sha256:1cbfd99feabf1d5f820e199d98170f9c6d86853518b9b7d357edeced2b89edb5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/diffutils/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/diffutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/diffutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/diffutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"diffutils","version":"1:3.3-3"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-53910","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-05","epss":0.00332,"percentile":0.241}],"risk":0.166,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53910"},"relatedVulnerabilities":[{"id":"CVE-2026-53910","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-05","epss":0.00332,"percentile":0.241}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-53910","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815","https://git.savannah.gnu.org/cgit/diffutils.git/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53910","description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"risk":0.1655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6791"},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"risk":0.1655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6791"},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"risk":0.1655,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6791"},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-05","epss":0.00331,"percentile":0.2398}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"risk":0.16155,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-39537"},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"risk":0.16155,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-39537"},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"risk":0.16155,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-39537"},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"risk":0.16155,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-39537"},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"risk":0.16155,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-39537"},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-05","epss":0.03231,"percentile":0.8784}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1752","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1752","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"risk":0.16049999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1752"},"relatedVulnerabilities":[{"id":"CVE-2020-1752","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":3.7,"impactScore":6.5,"exploitabilityScore":2},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://security.netapp.com/advisory/ntap-20200511-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=25414","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1752","description":"A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1752","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1752","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"risk":0.16049999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1752"},"relatedVulnerabilities":[{"id":"CVE-2020-1752","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":3.7,"impactScore":6.5,"exploitabilityScore":2},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://security.netapp.com/advisory/ntap-20200511-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=25414","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1752","description":"A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.23-0ubuntu11.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1752","versionConstraint":"< 2.23-0ubuntu11.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2020-1752","fix":{"state":"fixed","versions":["2.23-0ubuntu11.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.23-0ubuntu11.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"risk":0.16049999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1752"},"relatedVulnerabilities":[{"id":"CVE-2020-1752","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":3.7,"impactScore":6.5,"exploitabilityScore":2},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-1752","cwe":"CWE-416","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1752","date":"2026-10-05","epss":0.00535,"percentile":0.43164}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202101-20","https://security.netapp.com/advisory/ntap-20200511-0005/","https://sourceware.org/bugzilla/show_bug.cgi?id=25414","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1752","description":"A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32."}]},{"artifact":{"id":"223b23b613ccf0dd","cpes":["cpe:2.3:a:tar:tar:1.28-2.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.28-2.1?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"1.28-2.1","language":"","licenses":["sha256:9292780f2dfd11900e92ea67c7a316cf9df740b955956f87ec099a5b4f3d9136"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.28-2.1ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-20482","versionConstraint":"< 1.28-2.1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"tar","version":"1.28-2.1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2018-20482","fix":{"state":"fixed","versions":["1.28-2.1ubuntu0.2"],"available":[{"date":"2021-01-13","kind":"advisory","version":"1.28-2.1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-20482","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20482","date":"2026-10-05","epss":0.0053,"percentile":0.4287}],"risk":0.159,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-20482"},"relatedVulnerabilities":[{"id":"CVE-2018-20482","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20482","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20482","date":"2026-10-05","epss":0.0053,"percentile":0.4287}],"urls":["http://git.savannah.gnu.org/cgit/tar.git/commit/?id=c15c42ccd1e2377945fd0414eca1a49294bff454","http://lists.gnu.org/archive/html/bug-tar/2018-12/msg00023.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html","http://www.securityfocus.com/bid/106354","https://lists.debian.org/debian-lts-announce/2018/12/msg00023.html","https://lists.debian.org/debian-lts-announce/2021/11/msg00025.html","https://news.ycombinator.com/item?id=18745431","https://security.gentoo.org/glsa/201903-05","https://twitter.com/thatcks/status/1076166645708668928","https://utcc.utoronto.ca/~cks/space/blog/sysadmin/TarFindingTruncateBug"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20482","description":"GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root)."}]},{"artifact":{"id":"42899f1499942b30","cpes":["cpe:2.3:a:libpcre3:libpcre3:2\\:8.38-1ubuntu1:*:*:*:*:*:*:*"],"name":"libpcre3","purl":"pkg:deb/ubuntu/libpcre3@2%3A8.38-1ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=pcre3","type":"deb","version":"2:8.38-1ubuntu1","language":"","licenses":["sha256:ac9276490d2fa167442ae1aae33926514ad10c8886baa40046c5e367fccc5938"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre3/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libpcre3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libpcre3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-11164","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"pcre3","version":"2:8.38-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-11164","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-11164","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-11164","date":"2026-10-05","epss":0.03076,"percentile":0.87231}],"risk":0.15380000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-11164"},"relatedVulnerabilities":[{"id":"CVE-2017-11164","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-11164","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-11164","date":"2026-10-05","epss":0.03076,"percentile":0.87231}],"urls":["http://openwall.com/lists/oss-security/2017/07/11/3","http://www.openwall.com/lists/oss-security/2023/04/11/1","http://www.openwall.com/lists/oss-security/2023/04/12/1","http://www.securityfocus.com/bid/99575","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11164","description":"In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression."}]},{"artifact":{"id":"8b53eb2c7dd5c9fb","cpes":["cpe:2.3:a:dash:dash:0.5.7-4ubuntu2:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.7-4ubuntu2?arch=amd64&distro=ubuntu-16.04","type":"deb","version":"0.5.7-4ubuntu2","language":"","licenses":["sha256:7c77d28679de92b8aca0b3dd400eabac91bf9f6c68171e49355888d2593a968f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.config","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.config"},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.preinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.preinst"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.prerm"},{"path":"/var/lib/dpkg/info/dash.templates","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/dash.templates"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91187","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"dash","version":"0.5.7-4ubuntu2"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-91187","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91187","cwe":"CWE-347","type":"Secondary","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epss":[{"cve":"CVE-2026-91187","date":"2026-10-05","epss":0.00303,"percentile":0.20986}],"risk":0.1515,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91187"},"relatedVulnerabilities":[{"id":"CVE-2026-91187","cvss":[{"type":"Secondary","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91187","cwe":"CWE-347","type":"Secondary","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epss":[{"cve":"CVE-2026-91187","date":"2026-10-05","epss":0.00303,"percentile":0.20986}],"urls":["https://cna.erlef.org/cves/CVE-2026-91187.html","https://github.com/dashbitco/nimble_zta/commit/6458fd18a5ba41166d4973214c519e98fe05b72d","https://github.com/dashbitco/nimble_zta/commit/bc004b70985ae5763901baab3a4e204047899768","https://github.com/dashbitco/nimble_zta/security/advisories/GHSA-rj24-g8cc-g7g2","https://osv.dev/vulnerability/EEF-CVE-2026-91187"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91187","description":"Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected.\n\nverify_token/2 in lib/nimble_zta/cloudflare.ex matches the result of JOSE.JWT.verify/2 against {_, token, _s}, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the cf-access-jwt-assertion header, carrying the expected iss claim and the seven service token claims. verify_iss/2 reads the iss claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity.\n\nThis issue affects nimble_zta: from 0.1.2 before 0.1.3."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13729","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13729"},"relatedVulnerabilities":[{"id":"CVE-2017-13729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484276","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13729","description":"There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13730","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13730","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13730"},"relatedVulnerabilities":[{"id":"CVE-2017-13730","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484284","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13730","description":"There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13731","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13731","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13731"},"relatedVulnerabilities":[{"id":"CVE-2017-13731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484285","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13731","description":"There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack."}]},{"artifact":{"id":"29187ee7b39dd3e2","cpes":["cpe:2.3:a:libncurses5:libncurses5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncurses5","purl":"pkg:deb/ubuntu/libncurses5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncurses5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncurses5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13732","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13732","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13732"},"relatedVulnerabilities":[{"id":"CVE-2017-13732","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484287","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13732","description":"There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13729","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13729"},"relatedVulnerabilities":[{"id":"CVE-2017-13729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484276","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13729","description":"There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13730","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13730","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13730"},"relatedVulnerabilities":[{"id":"CVE-2017-13730","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484284","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13730","description":"There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13731","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13731","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13731"},"relatedVulnerabilities":[{"id":"CVE-2017-13731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484285","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13731","description":"There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack."}]},{"artifact":{"id":"f90c53cc16680893","cpes":["cpe:2.3:a:libncursesw5:libncursesw5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libncursesw5","purl":"pkg:deb/ubuntu/libncursesw5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libncursesw5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libncursesw5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13732","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13732","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13732"},"relatedVulnerabilities":[{"id":"CVE-2017-13732","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484287","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13732","description":"There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13729","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13729"},"relatedVulnerabilities":[{"id":"CVE-2017-13729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484276","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13729","description":"There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13730","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13730","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13730"},"relatedVulnerabilities":[{"id":"CVE-2017-13730","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484284","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13730","description":"There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13731","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13731","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13731"},"relatedVulnerabilities":[{"id":"CVE-2017-13731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484285","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13731","description":"There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack."}]},{"artifact":{"id":"98caf44f409fd254","cpes":["cpe:2.3:a:libtinfo5:libtinfo5:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"libtinfo5","purl":"pkg:deb/ubuntu/libtinfo5@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo5/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libtinfo5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libtinfo5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13732","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13732","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13732"},"relatedVulnerabilities":[{"id":"CVE-2017-13732","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484287","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13732","description":"There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13729","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13729"},"relatedVulnerabilities":[{"id":"CVE-2017-13729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484276","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13729","description":"There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13730","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13730","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13730"},"relatedVulnerabilities":[{"id":"CVE-2017-13730","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484284","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13730","description":"There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13731","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13731","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13731"},"relatedVulnerabilities":[{"id":"CVE-2017-13731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484285","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13731","description":"There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack."}]},{"artifact":{"id":"8feee0281440d6d4","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.0%2B20151024-2ubuntu1?arch=all&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13732","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13732","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13732"},"relatedVulnerabilities":[{"id":"CVE-2017-13732","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484287","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13732","description":"There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13729","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13729"},"relatedVulnerabilities":[{"id":"CVE-2017-13729","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13729","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13729","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484276","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13729","description":"There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13730","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13730","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13730"},"relatedVulnerabilities":[{"id":"CVE-2017-13730","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13730","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13730","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484284","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13730","description":"There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13731","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13731","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13731"},"relatedVulnerabilities":[{"id":"CVE-2017-13731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13731","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13731","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484285","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13731","description":"There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack."}]},{"artifact":{"id":"42f6bfe1c5f3de04","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.0\\+20151024-2ubuntu1:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.0%2B20151024-2ubuntu1?arch=amd64&distro=ubuntu-16.04&upstream=ncurses","type":"deb","version":"6.0+20151024-2ubuntu1","language":"","licenses":["sha256:54b583f76e36674808287a000797745e6bfd9fe1f82408906ae26ccc1adb643b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13732","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"ncurses","version":"6.0+20151024-2ubuntu1"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2017-13732","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"risk":0.14650000000000002,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13732"},"relatedVulnerabilities":[{"id":"CVE-2017-13732","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13732","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13732","date":"2026-10-05","epss":0.0293,"percentile":0.86619}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1484287","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/201804-13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13732","description":"There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack."}]},{"artifact":{"id":"dbfb5b6e3433027f","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c592442f397949fb","cpes":["cpe:2.3:a:libc6:libc6:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"8af0853a2cbcf4b0","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.21-0ubuntu5:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.21-0ubuntu5:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.21-0ubuntu5?arch=amd64&distro=ubuntu-16.04&upstream=glibc","type":"deb","version":"2.21-0ubuntu5","language":"","licenses":["sha256:a125a054ae06b4a35f5388da872faa61b5c197129a45ba4c7a18d2231ad94c8c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:572b78c15c672deb99f90334a7390643e95ec95ac2ddfc8707010395920c96cf","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"16.04"},"package":{"name":"glibc","version":"2.21-0ubuntu5"},"namespace":"ubuntu:distro:ubuntu:16.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:16.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-05","epss":0.00292,"percentile":0.19745}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]}],"grade":"F","score":"0.00","as_of":"2026-10-06T18:42:49.136Z","grype_db_version":"unknown"}