Mobyproject
Mobyproject Moby: vulnerabilidades y CVE
Mobyproject Moby tiene 21 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42306 | Alta (7.2) | 0.10% | — | 12 jun 2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount… |
| CVE-2026-41568 | Media (6.1) | 0.10% | — | 12 jun 2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount… |
| CVE-2025-54410 | Media (5.2) | 0.15% | — | 30 jul 2025 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects… |
| CVE-2025-54388 | Media (5.1) | 0.23% | — | 30 jul 2025 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2,… |
| CVE-2024-36623 | Alta (8.1) | 0.64% | — | 29 nov 2024 | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes. |
| CVE-2024-36621 | Media (6.5) | 0.63% | — | 29 nov 2024 | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource… |
| CVE-2024-36620 | Media (6.5) | 0.82% | — | 29 nov 2024 | moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go. |
| CVE-2024-32473 | Media (6.5) | 0.35% | — | 18 abr 2024 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces,… |
| CVE-2024-29018 | Alta (7.5) | 0.75% | — | 20 mar 2024 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks,… |
| CVE-2024-24557 | Alta (7.8) | 0.26% | — | 1 feb 2024 | Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions… |
| CVE-2023-28842 | Media (6.8) | 1.4% | — | 4 abr 2023 | Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`),… |
| CVE-2023-28841 | Media (6.8) | 0.69% | — | 4 abr 2023 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which… |
| CVE-2023-28840 | Alta (8.7) | 2.6% | — | 4 abr 2023 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which… |
| CVE-2022-36109 | Media (6.3) | 1.0% | — | 9 sept 2022 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a… |
| CVE-2022-27652 | Media (5.3) | 0.25% | — | 18 abr 2022 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable… |
| CVE-2022-24769 | Media (5.9) | 0.49% | — | 24 mar 2022 | Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with… |
| CVE-2021-41091 | Media (6.3) | 2.8% | — | 4 oct 2021 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with… |
| CVE-2021-41089 | Media (6.3) | 0.29% | — | 4 oct 2021 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can… |
| CVE-2018-12608 | Alta (7.5) | 0.92% | — | 10 sept 2018 | An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed… |
| CVE-2018-10892 | Media (5.3) | 1.1% | — | 6 jul 2018 | The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or… |
| CVE-2017-16539 | Media (5.9) | 1.8% | — | 4 nov 2017 | The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by… |