VYPR

rpm package

opensuse/skopeo&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/skopeo&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-34986HigApr 6, 2026
    affected < 1.22.1-1.1fixed 1.22.1-1.1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JW

  • CVE-2024-9676Oct 15, 2024
    affected < 1.16.1-2.1fixed 1.16.1-2.1

    A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned

  • CVE-2024-3727HigMay 14, 2024
    affected < 1.15.1-1.1fixed 1.15.1-1.1

    A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

  • CVE-2019-10214Nov 25, 2019
    affected < 1.2.3-1.2fixed 1.2.3-1.2

    The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulne

  • CVE-2017-14992MedNov 1, 2017
    affected < 1.2.3-1.2fixed 1.2.3-1.2

    Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.