Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.97%—Jenkins Docker Commons5/10/201717/6/2026
Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those…
ModificadaAlta (7.5)3.2%—Docker RegistryRedhat Enterprise Linux Server20/7/201717/6/2026
Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
ModificadaMedia (6.4)0.41%—Docker31/1/201717/6/2026
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC…
ModificadaMedia (5.5)3.5%—Docker2aci Project Docker2aci27/1/201717/6/2026
Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.
ModificadaMedia (6.5)2.8%—Docker4/1/201717/6/2026
The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the…
ModificadaAlta (7.5)2.8%—Docker28/10/201617/6/2026
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
ModificadaMedia (4)0.36%—Docker2aci Project Docker2aci28/10/201617/6/2026
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.
ModificadaAlta (7.8)0.39%—DockerLinuxfoundation RuncOpensuse1/6/201617/6/2026
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
ModificadaBaja (3.6)0.57%—Docker18/5/201517/6/2026
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
ModificadaAlta (7.2)0.55%—Docker18/5/201517/6/2026
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
ModificadaAlta (7.8)0.60%—Docker LibcontainerOpensuse18/5/201517/6/2026
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
ModificadaAlta (7.2)0.61%—DockerDocker Libcontainer18/5/201517/6/2026
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
ModificadaMedia (4.3)1.6%—Redhat Docker6/4/201517/6/2026
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and…
ModificadaMedia (6.4)2.5%—Docker16/12/201417/6/2026
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
ModificadaAlta (10)6.2%—Docker16/12/201417/6/2026
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
ModificadaMedia (5)3.1%—Docker12/12/201417/6/2026
Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.
ModificadaAlta (7.5)4.9%—Docker12/12/201417/6/2026
Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
ModificadaMedia (5)1.9%—DockerDocker-py17/11/201417/6/2026
Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.
ModificadaAlta (7.2)0.39%—DockerFedoraproject Fedora11/7/201417/6/2026
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.
ModificadaAlta (7.2)0.35%—Kdocker31/12/200416/6/2026
kdocker.cpp in kdocker 0.1 through 0.8 does not properly check the ownership of files, which could allow local users to execute arbitrary programs.
Orbitaley — Vulnerabilidades