Ocimendby CloudTrace

Image reports › ocimend.io/wordpress

ocimend.io/wordpress — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/wordpress · Debian GNU/Linux 12 (bookworm)

Latest: ocimend.io/wordpress:6.8.1-php8.3-apache-fips · checked 2026-09-26

Not FIPS-ready

No. wordpress:6.8.1-php8.3-apache-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 660 known vulnerabilities

660 known vulnerabilities in 104 packages (5 critical, 87 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in 6.8.1-php8.3-apache-fips

SeverityIDPackageFixed inSummary
criticalCVE-2024-5535libssl3 3.0.16-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-5535openssl 3.0.16-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2023-45853zlib1g 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe
criticalCVE-2023-6879libaom3 3.6.0-1+deb12u1no fix yetIncreasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
criticalCVE-2024-38541linux-libc-dev 6.1.140-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2019-19814linux-libc-dev 6.1.140-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
highCVE-2023-52356libtiff6 4.5.0-6+deb12u2no fix yetA segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
highCVE-2019-19449linux-libc-dev 6.1.140-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).
highCVE-2023-2953libldap-2.5-0 2.5.13+dfsg-5no fix yetA vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
highCVE-2023-52355libtiff6 4.5.0-6+deb12u2no fix yetAn out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
highCVE-2023-52425libexpat1 2.5.0-1+deb12u1no fix yetlibexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
highCVE-2023-31484libperl5.36 5.36.0-7+deb12u2no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2023-31484perl 5.36.0-7+deb12u2no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2023-31484perl-base 5.36.0-7+deb12u2no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2023-31484perl-modules-5.36 5.36.0-7+deb12u2no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
6.8.1-php8.3-apache-fipsNot FIPS-readyA 660 5 critical2026-09-26Full report