Show filters
95 Total Results
Displaying 81-90 of 95
Sort by:
Attacker Value
Unknown

CVE-2016-6595

Disclosure Date: January 04, 2017 (last updated November 08, 2023)
The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the manager obviously stops being able to accept new nodes, since it runs out of memory. Given that both for Docker swarm and for Docker Swarmkit nodes are *required* to provide a secret token (it's actually the only mode of operation), this means that no adversary can simply join nodes and exhaust manager resources. We can't do anything about a manager running out of memory and not being able to add new legitimate nodes to the system. This is merely a resource provisioning issue, and definitely not a CVE worthy vulnerability.
0
Attacker Value
Unknown

CVE-2016-8867

Disclosure Date: October 28, 2016 (last updated November 25, 2024)
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
0
Attacker Value
Unknown

CVE-2016-8579

Disclosure Date: October 28, 2016 (last updated November 25, 2024)
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.
0
Attacker Value
Unknown

CVE-2016-3697

Disclosure Date: June 01, 2016 (last updated November 25, 2024)
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
Attacker Value
Unknown

CVE-2015-3629

Disclosure Date: May 18, 2015 (last updated February 02, 2024)
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
Attacker Value
Unknown

CVE-2015-3631

Disclosure Date: May 18, 2015 (last updated October 05, 2023)
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
0
Attacker Value
Unknown

CVE-2015-3630

Disclosure Date: May 18, 2015 (last updated October 05, 2023)
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
0
Attacker Value
Unknown

CVE-2015-3627

Disclosure Date: May 18, 2015 (last updated October 05, 2023)
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
0
Attacker Value
Unknown

CVE-2014-9357

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
0
Attacker Value
Unknown

CVE-2014-9358

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
0