Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown

CVE-2015-9259

Disclosure Date: March 31, 2018 (last updated November 26, 2024)
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file.
0
Attacker Value
Unknown

CVE-2015-9258

Disclosure Date: March 31, 2018 (last updated November 26, 2024)
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.
0
Attacker Value
Unknown

CVE-2014-5282

Disclosure Date: February 06, 2018 (last updated November 08, 2023)
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
0
Attacker Value
Unknown

CVE-2014-5279

Disclosure Date: February 06, 2018 (last updated November 08, 2023)
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
0
Attacker Value
Unknown

CVE-2014-5280

Disclosure Date: February 06, 2018 (last updated November 08, 2023)
boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.
Attacker Value
Unknown

CVE-2017-14992

Disclosure Date: November 01, 2017 (last updated February 15, 2024)
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.
0
Attacker Value
Unknown

CVE-2014-0047

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.
0
Attacker Value
Unknown

CVE-2017-11468

Disclosure Date: July 20, 2017 (last updated November 26, 2024)
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
Attacker Value
Unknown

CVE-2016-9962

Disclosure Date: January 31, 2017 (last updated November 08, 2023)
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
0
Attacker Value
Unknown

CVE-2016-7569

Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.
0