Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Docker Desktop HIGH 7.8
CVE-2023-0628

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking…

Fix: 4.17.0+
Fix from $1,950 2023-03-13
Docker Desktop HIGH 8.4
CVE-2021-44719

Docker Desktop 4.3.0 has Incorrect Access Control.

Fix: 4.5.0+
Fix from $1,950 2022-05-25
Docker Desktop HIGH 7.1
CVE-2022-26659

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink i…

Fix: 4.6.0+
Fix from $1,950 2022-03-25
Docker HIGH 7.8
CVE-2022-25365

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23…

Fix: 4.5.1+
Fix from $1,950 2022-02-19
Docker Desktop MEDIUM 5.3
CVE-2022-23774

Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.

Fix: 4.4.4+
Fix from $1,600 2022-02-01
Docker Desktop MEDIUM 5.5
CVE-2021-45449

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th…

Mitigation only
Fix from $1,600 2022-01-12
Command Line Interface HIGH 7.5
CVE-2021-41092

Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r…

Fix: 20.10.9+
Fix from $1,950 2021-10-04
Desktop HIGH 7.8
CVE-2021-37841

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows conta…

Fix: 3.6.0+
Fix from $1,950 2021-08-12
Docker MEDIUM 6.5
CVE-2021-21285

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the doc…

Fix: 19.03.15 / 20.10.3+
Fix from $1,600 2021-02-02
Docker MEDIUM 6.8
CVE-2021-21284

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privi…

Fix: 19.03.15 / 20.10.3+
Fix from $1,600 2021-02-02
Docker HIGH 7.8
CVE-2021-3162

Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.

Fix: 2.5.0.0+
Fix from $1,950 2021-01-15
Docker MEDIUM 5.3
CVE-2020-27534

util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, const…

Fix: 19.03.9+
Fix from $1,600 2020-12-30
Haproxy Docker Image CRITICAL 9.8
CVE-2020-35195

The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker c…

Fix: 1.8.18+
Fix from $2,300 2020-12-17
Rabbitmq Docker Image CRITICAL 9.8
CVE-2020-35196

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using t…

Fix: after 3.7.12
Fix from $2,300 2020-12-17
Memcached Docker Image CRITICAL 9.8
CVE-2020-35197

The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached dock…

Fix: 1.5.11+
Fix from $2,300 2020-12-17
Composer Docker Image CRITICAL 9.8
CVE-2020-35184

The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by aff…

Fix: 1.8.3+
Fix from $2,300 2020-12-17
Adminer CRITICAL 9.8
CVE-2020-35186

The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed …

Fix: 4.7.0-fastcgi+
Fix from $2,300 2020-12-17
Ghost Alpine Docker Image CRITICAL 9.8
CVE-2020-35185

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker conta…

Fix: 2.16.1+
Fix from $2,300 2020-12-17
Docs CRITICAL 9.8
CVE-2020-35467

The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker D…

Fix: after 2020-12-14
Fix from $2,300 2020-12-15
Registry CRITICAL 9.8
CVE-2020-29591

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of…

Mitigation only
Fix from $2,300 2020-12-11
Storm Docker Image CRITICAL 9.8
CVE-2020-29580

The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected…

Fix: 1.2.1+
Fix from $2,300 2020-12-08
Spiped Alpine Docker Image CRITICAL 9.8
CVE-2020-29581

The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by a…

Fix: 1.5+
Fix from $2,300 2020-12-08
Notary Docker Image CRITICAL 9.8
CVE-2020-29601

The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed b…

Mitigation only
Fix from $2,300 2020-12-08
Elixir Alpine Docker Image CRITICAL 9.8
CVE-2020-29575

The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Dock…

Fix: 1.8.0+
Fix from $2,300 2020-12-08
Crux Linux Docker Image CRITICAL 9.8
CVE-2020-29389

The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed…

Fix: after 3.4
Fix from $2,300 2020-12-02
Docker HIGH 8.8
CVE-2020-14300

The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.red…

Mitigation only
Fix from $1,950 2020-07-13
Docker HIGH 8.8
CVE-2020-14298

The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the…

Fix: after 3.7.61
Fix from $1,950 2020-07-13
Docker Desktop HIGH 7.8
CVE-2020-15360

com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.

No fix yet
Fix from $1,950 2020-06-27
Docker Desktop HIGH 7.8
CVE-2020-11492

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with …

Fix: after 2.2.0.5
Fix from $1,950 2020-06-05
Engine MEDIUM 6.0
CVE-2020-13401

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertis…

Fix: 19.03.11+
Fix from $1,600 2020-06-02