Image reports › ocimend.io/wordpress
ocimend.io/wordpress — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/wordpress · Debian GNU/Linux 12 (bookworm)
Latest: ocimend.io/wordpress:6.8.1-php8.3-apache-fips · checked 2026-09-26
Not FIPS-ready
No. wordpress:6.8.1-php8.3-apache-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 660 known vulnerabilities
660 known vulnerabilities in 104 packages (5 critical, 87 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in 6.8.1-php8.3-apache-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-5535 | libssl3 3.0.16-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.16-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| critical | CVE-2023-6879 | libaom3 3.6.0-1+deb12u1 | no fix yet | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). |
| critical | CVE-2024-38541 | linux-libc-dev 6.1.140-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2019-19814 | linux-libc-dev 6.1.140-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. |
| high | CVE-2023-52356 | libtiff6 4.5.0-6+deb12u2 | no fix yet | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service. |
| high | CVE-2019-19449 | linux-libc-dev 6.1.140-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated). |
| high | CVE-2023-2953 | libldap-2.5-0 2.5.13+dfsg-5 | no fix yet | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
| high | CVE-2023-52355 | libtiff6 4.5.0-6+deb12u2 | no fix yet | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. |
| high | CVE-2023-52425 | libexpat1 2.5.0-1+deb12u1 | no fix yet | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. |
| high | CVE-2023-31484 | libperl5.36 5.36.0-7+deb12u2 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2023-31484 | perl 5.36.0-7+deb12u2 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2023-31484 | perl-base 5.36.0-7+deb12u2 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2023-31484 | perl-modules-5.36 5.36.0-7+deb12u2 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 6.8.1-php8.3-apache-fips | Not FIPS-ready | A 660 5 critical | 2026-09-26 | Full report |