Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.7 CVE-2020-10665 Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privil… Desktop 2.1.0.9 / 2.2.0.4+ Fix from $1,6002020-03-18 MEDIUM 5.3 CVE-2014-5278 A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs. Docker 1.2.0+ Fix from $1,6002020-02-07 CRITICAL 9.8 CVE-2014-0048EPSS 7% An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. Docker 1.5.0+ Fix from $2,3002020-01-02 HIGH 7.5 CVE-2014-8179 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representat… Cs Engine 1.6.2-cs7 / 1.8.3+ Fix from $1,9502019-12-17 MEDIUM 5.5 CVE-2014-8178 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier… Cs Engine 1.6.2-cs7 / 1.8.3+ Fix from $1,6002019-12-17 HIGH 8.6 CVE-2014-9356 Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism v… Docker 1.3.3+ Fix from $1,9502019-12-02 HIGH 7.5 CVE-2019-16884 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux… Docker after 19.03.2 Fix from $1,9502019-09-25 HIGH 7.8 CVE-2019-15752 KEVEPSS 32% Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in… Docker 2.1.0.1+ Fix from $1,9502019-08-28 HIGH 8.4 CVE-2019-13139 In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain… Docker 18.09.4+ Fix from $1,9502019-08-22 CRITICAL 9.8 CVE-2019-14271EPSS 19% In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads … Docker 19.03.1+ Fix from $2,3002019-07-29 MEDIUM 5.5 CVE-2019-1020014 docker-credential-helpers before 0.6.3 has a double free in the List functions. Credential Helpers 0.6.3+ Fix from $1,6002019-07-29 HIGH 7.5 CVE-2019-13509 In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometim… Docker 18.09.8+ Fix from $1,9502019-07-18 HIGH 7.5 CVE-2018-15664 In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Travers… Docker Patch available Fix from $1,9502019-05-23 HIGH 8.6 CVE-2019-5736EPSS 98% runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtai… Docker 1.4.3 / 1.5.3+ Fix from $1,9502019-02-11 HIGH 8.8 CVE-2018-15514 HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\p… Docker No fix yet Fix from $1,9502018-09-01 MEDIUM 5.3 CVE-2018-10892 The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an att… Docker after 18.03.1 Fix from $1,6002018-07-06 CRITICAL 9.8 CVE-2015-9259 In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating tha… Notary 0.1+ Fix from $2,3002018-03-31 HIGH 7.5 CVE-2015-9258 In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the fiel… Notary 0.1+ Fix from $1,9502018-03-31 HIGH 8.1 CVE-2014-5282 Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted i… Docker 1.3+ Fix from $1,9502018-02-06 MEDIUM 6.5 CVE-2017-14992 Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09… Docker after 1.10.3 Fix from $1,6002017-11-01 HIGH 7.8 CVE-2014-0047 Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. Docker after 1.4.1 Fix from $1,9502017-10-06 HIGH 7.5 CVE-2017-11468 Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attack… Docker Registry after 2.6.1 Fix from $1,9502017-07-20 MEDIUM 6.4 CVE-2016-9962 RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the conta… Docker 1.12.6+ Fix from $1,6002017-01-31 MEDIUM 6.5 CVE-2016-6595 The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequen… Docker Mitigation only Fix from $1,6002017-01-04 HIGH 7.5 CVE-2016-8867 Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to… Docker Mitigation only Fix from $1,9502016-10-28 HIGH 7.8 CVE-2016-3697 libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allow… Docker after 1.11.1 Fix from $1,9502016-06-01 HIGH 7.2 CVE-2015-3630 Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows… Docker after 1.6 Fix from $1,9502015-05-18 HIGH 7.8 CVE-2015-3629 Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file … Libcontainer No fix yet Fix from $1,9502015-05-18 HIGH 7.2 CVE-2015-3627 Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local us… Docker after 1.6.0 Fix from $1,9502015-05-18 MEDIUM 6.4 CVE-2014-9358 Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via … Docker after 1.3.2 Fix from $1,6002014-12-16