CVE-2025-55473
- EPSS 0.03%
- Published 02.09.2025 00:00:00
- Last modified 04.09.2025 15:36:56
Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without pr...
CVE-2022-25365
- EPSS 1.88%
- Published 19.02.2022 02:15:06
- Last modified 21.11.2024 06:52:05
Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.
CVE-2021-21285
- EPSS 0.12%
- Published 02.02.2021 18:15:12
- Last modified 21.11.2024 05:47:56
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
CVE-2021-21284
- EPSS 0.02%
- Published 02.02.2021 18:15:11
- Last modified 21.11.2024 05:47:55
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace...
CVE-2021-3162
- EPSS 0.02%
- Published 15.01.2021 22:15:13
- Last modified 21.11.2024 06:21:02
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2020-27534
- EPSS 0.77%
- Published 30.12.2020 23:15:15
- Last modified 21.11.2024 05:21:19
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
CVE-2020-14300
- EPSS 0.29%
- Published 13.07.2020 22:15:12
- Last modified 21.11.2024 05:02:57
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug an...
CVE-2020-14298
- EPSS 0.14%
- Published 13.07.2020 21:15:14
- Last modified 21.11.2024 05:02:57
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malic...
CVE-2014-5278
- EPSS 0.44%
- Published 07.02.2020 18:15:10
- Last modified 21.11.2024 02:11:46
A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.
CVE-2014-0048
- EPSS 3.32%
- Published 02.01.2020 17:15:10
- Last modified 21.11.2024 02:01:14
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.