VYPR

apk package

chainguard/neuvector-sigstore-interface

pkg:apk/chainguard/neuvector-sigstore-interface

Vulnerabilities (84)

  • CVE-2024-24789MedJun 5, 2024
    affected < 0_git20240520-r2fixed 0_git20240520-r2

    The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip pac

  • CVE-2024-29903MedApr 10, 2024
    affected < 0_git20240520-r1fixed 0_git20240520-r1

    Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine running Cosign thereby impacting all services on the machine. The root cause is that Cosign creates

  • CVE-2024-29902MedApr 10, 2024
    affected < 0_git20240520-r1fixed 0_git20240520-r1

    Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cause denial of service of the host machine running Cosign. This can impact other services on the machine that rely on having memory a

  • CVE-2023-45288HigApr 4, 2024
    affected < 0_git20240520-r1fixed 0_git20240520-r1

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed Ma

Page 5 of 5