Search CVE reports


Toggle filters

41 – 50 of 62 results


CVE-2017-14992

Low priority

Some fixes available 16 of 19

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a...

2 affected packages

docker.io, golang-github-vbatts-tar-split

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed
golang-github-vbatts-tar-split Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-9962

Medium priority

Some fixes available 11 of 13

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new...

2 affected packages

runc, docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
runc Fixed
docker.io Fixed
Show less packages

CVE-2016-6595

Medium priority
Not affected

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that...

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2016-3697

Medium priority

Some fixes available 1 of 4

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a...

2 affected packages

docker.io, runc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
runc
Show less packages

CVE-2015-3631

Medium priority

Some fixes available 2 of 6

Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2015-3630

Medium priority

Some fixes available 2 of 6

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and...

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2015-3629

Medium priority

Some fixes available 2 of 6

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2015-3627

Medium priority

Some fixes available 1 of 5

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2015-1843

Medium priority
Not affected

The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain...

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2014-9358

Medium priority
Ignored

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

1 affected package

docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages