CVE-2018-15514
- EPSS 5.48%
- Veröffentlicht 01.09.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:59
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This wo...
CVE-2018-10892
- EPSS 0.19%
- Veröffentlicht 06.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:14
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightn...
CVE-2014-5282
- EPSS 0.41%
- Veröffentlicht 06.02.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:11:47
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
CVE-2017-14992
- EPSS 0.18%
- Veröffentlicht 01.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer paylo...
CVE-2014-0047
- EPSS 0.11%
- Veröffentlicht 06.10.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.
CVE-2016-9962
- EPSS 0.2%
- Veröffentlicht 31.01.2017 22:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initia...
CVE-2016-6595
- EPSS 0.65%
- Veröffentlicht 04.01.2017 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not...
CVE-2016-8867
- EPSS 0.37%
- Veröffentlicht 28.10.2016 15:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVE-2016-3697
- EPSS 0.09%
- Veröffentlicht 01.06.2016 20:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVE-2015-3631
- EPSS 0.12%
- Veröffentlicht 18.05.2015 15:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.