Search CVE reports


Toggle filters

51 – 60 of 70 results


CVE-2018-12608

Low priority
Fixed

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed
Show less packages

CVE-2018-10892

Medium priority

Some fixes available 3 of 4

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed
Show less packages

CVE-2014-5282

Medium priority
Ignored

Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2017-16539

Medium priority

Some fixes available 3 of 5

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed
Show less packages

CVE-2017-14992

Low priority

Some fixes available 18 of 20

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a...

2 affected packages

docker.io, golang-github-vbatts-tar-split

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed Fixed
golang-github-vbatts-tar-split Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2014-0047

Low priority

Some fixes available 2 of 6

Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2016-9962

Medium priority

Some fixes available 11 of 13

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new...

2 affected packages

docker.io, runc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed
runc Fixed
Show less packages

CVE-2016-6595

Medium priority
Not affected

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2016-3697

Medium priority

Some fixes available 1 of 4

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a...

2 affected packages

docker.io, runc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
runc
Show less packages

CVE-2015-3631

Medium priority

Some fixes available 2 of 6

Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages