Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Desktop HIGH 7.5
CVE-2023-1802

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed.…

No fix yet
Fix from $1,950 2023-04-06
Docker Desktop MEDIUM 5.5
CVE-2021-45449

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th…

Mitigation only
Fix from $1,600 2022-01-12
Registry CRITICAL 9.8
CVE-2020-29591

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of…

Mitigation only
Fix from $2,300 2020-12-11
Notary Docker Image CRITICAL 9.8
CVE-2020-29601

The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed b…

Mitigation only
Fix from $2,300 2020-12-08
Docker HIGH 8.8
CVE-2020-14300

The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.red…

Mitigation only
Fix from $1,950 2020-07-13
Docker Desktop HIGH 7.8
CVE-2020-15360

com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.

No fix yet
Fix from $1,950 2020-06-27
Docker HIGH 8.8
CVE-2018-15514

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\p…

No fix yet
Fix from $1,950 2018-09-01
Docker MEDIUM 6.5
CVE-2016-6595

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequen…

Mitigation only
Fix from $1,600 2017-01-04
Docker HIGH 7.5
CVE-2016-8867

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to…

Mitigation only
Fix from $1,950 2016-10-28
Libcontainer HIGH 7.8
CVE-2015-3629

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file …

No fix yet
Fix from $1,950 2015-05-18
Docker HIGH 10.0
CVE-2014-9357EPSS 6%

Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (…

Mitigation only
Fix from $1,950 2014-12-16
Docker MEDIUM 5.0
CVE-2014-6408

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applyin…

Mitigation only
Fix from $1,600 2014-12-12
Docker HIGH 7.2
CVE-2014-3499

Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified…

Mitigation only
Fix from $1,950 2014-07-11