Lucene search

K

Alpine Security Vulnerabilities

cve
cve

CVE-2022-23554

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains...

6.5CVSS

5.5AI Score

0.001EPSS

2022-12-28 07:15 PM
32
cve
cve

CVE-2022-23553

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known...

7.5CVSS

7.5AI Score

0.001EPSS

2022-12-28 07:15 PM
31
cve
cve

CVE-2021-46853

Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before...

5.9CVSS

5.6AI Score

0.004EPSS

2022-11-03 06:15 AM
36
6
cve
cve

CVE-2018-1000849

Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data....

8.8CVSS

9AI Score

0.016EPSS

2022-10-03 04:21 PM
23
cve
cve

CVE-2022-36347

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at...

5.4CVSS

5.2AI Score

0.001EPSS

2022-08-23 04:15 PM
45
5
cve
cve

CVE-2017-20087

A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched...

6.1CVSS

5.9AI Score

0.001EPSS

2022-06-23 05:15 AM
19
8
cve
cve

CVE-2022-22704

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the...

9.8CVSS

9.6AI Score

0.002EPSS

2022-01-06 05:15 AM
108
cve
cve

CVE-2021-38370

In Alpine before 2.25, untagged responses from an IMAP server are accepted before...

5.9CVSS

5.6AI Score

0.002EPSS

2021-08-10 03:15 PM
80
cve
cve

CVE-2020-35185

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank...

9.8CVSS

9.5AI Score

0.007EPSS

2020-12-17 01:15 AM
34
cve
cve

CVE-2020-35189

The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank...

9.8CVSS

9.5AI Score

0.007EPSS

2020-12-17 01:15 AM
35
2
cve
cve

CVE-2020-29581

The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank...

9.8CVSS

9.5AI Score

0.007EPSS

2020-12-08 04:15 PM
23
2
cve
cve

CVE-2020-29575

The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank...

9.8CVSS

9.5AI Score

0.007EPSS

2020-12-08 04:15 PM
18
2
cve
cve

CVE-2020-29578

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root...

9.8CVSS

9.5AI Score

0.007EPSS

2020-12-08 03:15 PM
27
4
cve
cve

CVE-2020-14929

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to...

7.5CVSS

7.2AI Score

0.009EPSS

2020-06-19 07:15 PM
152
cve
cve

CVE-2015-9432

The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab...

6.5CVSS

6.2AI Score

0.002EPSS

2019-09-26 02:15 AM
122
cve
cve

CVE-2019-5021

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the root user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux...

9.8CVSS

9.3AI Score

0.01EPSS

2019-05-08 05:29 PM
131
7
cve
cve

CVE-2017-9671

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header...

7.8CVSS

7.7AI Score

0.024EPSS

2017-07-17 09:29 PM
49
cve
cve

CVE-2017-9669

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz...

7.8CVSS

7.9AI Score

0.024EPSS

2017-07-17 09:29 PM
53
cve
cve

CVE-2008-5005

Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail...

7.7AI Score

0.118EPSS

2008-11-10 02:12 PM
41