Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Desktop MEDIUM 6.7
CVE-2020-10665

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privil…

Fix: 2.1.0.9 / 2.2.0.4+
Fix from $1,600 2020-03-18
Docker MEDIUM 5.3
CVE-2014-5278

A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.

Fix: 1.2.0+
Fix from $1,600 2020-02-07
Docker CRITICAL 9.8
CVE-2014-0048EPSS 7%

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

Fix: 1.5.0+
Fix from $2,300 2020-01-02
Cs Engine HIGH 7.5
CVE-2014-8179

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representat…

Fix: 1.6.2-cs7 / 1.8.3+
Fix from $1,950 2019-12-17
Cs Engine MEDIUM 5.5
CVE-2014-8178

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier…

Fix: 1.6.2-cs7 / 1.8.3+
Fix from $1,600 2019-12-17
Docker HIGH 8.6
CVE-2014-9356

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism v…

Fix: 1.3.3+
Fix from $1,950 2019-12-02
Docker HIGH 7.5
CVE-2019-16884

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux…

Fix: after 19.03.2
Fix from $1,950 2019-09-25
Docker HIGH 7.8
CVE-2019-15752 KEVEPSS 32%

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in…

Fix: 2.1.0.1+
Fix from $1,950 2019-08-28
Docker HIGH 8.4
CVE-2019-13139

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain…

Fix: 18.09.4+
Fix from $1,950 2019-08-22
Docker CRITICAL 9.8
CVE-2019-14271EPSS 19%

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads …

Fix: 19.03.1+
Fix from $2,300 2019-07-29
Credential Helpers MEDIUM 5.5
CVE-2019-1020014

docker-credential-helpers before 0.6.3 has a double free in the List functions.

Fix: 0.6.3+
Fix from $1,600 2019-07-29
Docker HIGH 7.5
CVE-2019-13509

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometim…

Fix: 18.09.8+
Fix from $1,950 2019-07-18
Docker HIGH 7.5
CVE-2018-15664

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Travers…

Patch available
Fix from $1,950 2019-05-23
Docker HIGH 8.6
CVE-2019-5736EPSS 98%

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtai…

Fix: 1.4.3 / 1.5.3+
Fix from $1,950 2019-02-11
Docker HIGH 8.8
CVE-2018-15514

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\p…

No fix yet
Fix from $1,950 2018-09-01
Docker MEDIUM 5.3
CVE-2018-10892

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an att…

Fix: after 18.03.1
Fix from $1,600 2018-07-06
Notary CRITICAL 9.8
CVE-2015-9259

In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating tha…

Fix: 0.1+
Fix from $2,300 2018-03-31
Notary HIGH 7.5
CVE-2015-9258

In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the fiel…

Fix: 0.1+
Fix from $1,950 2018-03-31
Docker HIGH 8.1
CVE-2014-5282

Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted i…

Fix: 1.3+
Fix from $1,950 2018-02-06
Docker MEDIUM 6.5
CVE-2017-14992

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09…

Fix: after 1.10.3
Fix from $1,600 2017-11-01
Docker HIGH 7.8
CVE-2014-0047

Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.

Fix: after 1.4.1
Fix from $1,950 2017-10-06
Docker Registry HIGH 7.5
CVE-2017-11468

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attack…

Fix: after 2.6.1
Fix from $1,950 2017-07-20
Docker MEDIUM 6.4
CVE-2016-9962

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the conta…

Fix: 1.12.6+
Fix from $1,600 2017-01-31
Docker MEDIUM 6.5
CVE-2016-6595

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequen…

Mitigation only
Fix from $1,600 2017-01-04
Docker HIGH 7.5
CVE-2016-8867

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to…

Mitigation only
Fix from $1,950 2016-10-28
Docker HIGH 7.8
CVE-2016-3697

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allow…

Fix: after 1.11.1
Fix from $1,950 2016-06-01
Docker HIGH 7.2
CVE-2015-3630

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows…

Fix: after 1.6
Fix from $1,950 2015-05-18
Libcontainer HIGH 7.8
CVE-2015-3629

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file …

No fix yet
Fix from $1,950 2015-05-18
Docker HIGH 7.2
CVE-2015-3627

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local us…

Fix: after 1.6.0
Fix from $1,950 2015-05-18
Docker MEDIUM 6.4
CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via …

Fix: after 1.3.2
Fix from $1,600 2014-12-16