VYPR

apk package

chainguard/grafana-10.4-oci-compat

pkg:apk/chainguard/grafana-10.4-oci-compat

Vulnerabilities (49)

  • CVE-2024-24789MedJun 5, 2024
    affected < 10.4.3-r2fixed 10.4.3-r2

    The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip pac

  • CVE-2023-45288HigApr 4, 2024
    affected < 10.4.1-r1fixed 10.4.1-r1

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed Ma

  • CVE-2024-28180MedMar 9, 2024
    affected < 10.4.8-r0fixed 10.4.8-r0

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now ret

  • CVE-2019-3826MedMar 26, 2019
    affected < 0fixed 0

    A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scri

  • CVE-2018-20677MedJan 9, 2019
    affected < 10.4.19.01-r4fixed 10.4.19.01-r4

    In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

  • CVE-2018-20676MedJan 9, 2019
    affected < 10.4.19.01-r4fixed 10.4.19.01-r4

    In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

  • CVE-2016-10735MedJan 9, 2019
    affected < 10.4.19.01-r4fixed 10.4.19.01-r4

    In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

  • CVE-2018-14042MedJul 13, 2018
    affected < 10.4.19.01-r4fixed 10.4.19.01-r4

    In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

  • CVE-2018-14040MedJul 13, 2018
    affected < 10.4.19.01-r4fixed 10.4.19.01-r4

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Page 3 of 3