Search CVE reports


Toggle filters

31 – 40 of 67 results


CVE-2020-15157

Medium priority
Fixed

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for...

2 affected packages

containerd, docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected
docker.io Fixed Fixed
Show less packages

CVE-2020-14300

Low priority
Not affected

The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected Not affected
Show less packages

CVE-2020-14298

Low priority
Not affected

The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected Not affected
Show less packages

CVE-2020-13401

Medium priority

Some fixes available 14 of 16

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information,...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2014-5278

Medium priority
Not affected

A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected
Show less packages

CVE-2014-0048

Low priority

Some fixes available 3 of 7

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2014-8179

Low priority

Some fixes available 2 of 5

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2014-8178

Low priority

Some fixes available 2 of 5

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected
Show less packages

CVE-2014-9356

High priority
Ignored

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io
Show less packages

CVE-2019-15752

Medium priority
Not affected

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and...

1 affected package

docker.io

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected
Show less packages