Docker
docker
97 CVEs • 27 products
Products (27)
Click to collapseToggle
Products (27)
Click to collapse
CVEs (97)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary fi...Show more |
A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs. |
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. |
2Docker Opensuse3Cs Engine DockerOpensuseNov 21, 2024 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a...Show more |
2Docker Opensuse3Cs Engine DockerOpensuseNov 21, 2024 Dec 17, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or...Show more |
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Docke...Show more |
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and...Show more |
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes...Show more |
3Debian DockerOpensuse3Debian Linux DockerLeapJun 17, 2026 Jul 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container. |
3Canonical DockerFedoraproject3Credential Helpers FedoraUbuntu LinuxJun 17, 2026 Jul 29, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 docker-credential-helpers before 0.6.3 has a double free in the List functions. |
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docke...Show more |
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem...Show more |
13Apache CanonicalD2iq+10 more19Backports Sle Container Development KitDc/os+16 moreJun 17, 2026 Feb 11, 2019 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more |
2Docker Redhat2Engine Enterprise Linux ServerNov 21, 2024 Jan 12, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.g...Show more |
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the dese...Show more |
4Docker MobyprojectOpensuse+1 more6Docker Enterprise LinuxEnterprise Linux Server+3 moreNov 21, 2024 Jul 6, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or tu...Show more |
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key comp...Show more |
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able...Show more |
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'. |