Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.97% | — | Jenkins Docker Commons | 5/10/2017 | 17/6/2026 | Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those… | |
| Modificada | Alta (7.5) | 3.2% | — | Docker RegistryRedhat Enterprise Linux Server | 20/7/2017 | 17/6/2026 | Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint. | |
| Modificada | Media (6.4) | 0.41% | — | Docker | 31/1/2017 | 17/6/2026 | RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC… | |
| Modificada | Media (5.5) | 3.5% | — | Docker2aci Project Docker2aci | 27/1/2017 | 17/6/2026 | Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image. | |
| Modificada | Media (6.5) | 2.8% | — | Docker | 4/1/2017 | 17/6/2026 | The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the… | |
| Modificada | Alta (7.5) | 2.8% | — | Docker | 28/10/2016 | 17/6/2026 | Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes. | |
| Modificada | Media (4) | 0.36% | — | Docker2aci Project Docker2aci | 28/10/2016 | 17/6/2026 | docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain. | |
| Modificada | Alta (7.8) | 0.39% | — | DockerLinuxfoundation RuncOpensuse | 1/6/2016 | 17/6/2026 | libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container. | |
| Modificada | Baja (3.6) | 0.57% | — | Docker | 18/5/2015 | 17/6/2026 | Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc. | |
| Modificada | Alta (7.2) | 0.55% | — | Docker | 18/5/2015 | 17/6/2026 | Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image. | |
| Modificada | Alta (7.8) | 0.60% | — | Docker LibcontainerOpensuse | 18/5/2015 | 17/6/2026 | Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container. | |
| Modificada | Alta (7.2) | 0.61% | — | DockerDocker Libcontainer | 18/5/2015 | 17/6/2026 | Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image. | |
| Modificada | Media (4.3) | 1.6% | — | Redhat Docker | 6/4/2015 | 17/6/2026 | The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and… | |
| Modificada | Media (6.4) | 2.5% | — | Docker | 16/12/2014 | 17/6/2026 | Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications." | |
| Modificada | Alta (10) | 6.2% | — | Docker | 16/12/2014 | 17/6/2026 | Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction. | |
| Modificada | Media (5) | 3.1% | — | Docker | 12/12/2014 | 17/6/2026 | Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image. | |
| Modificada | Alta (7.5) | 4.9% | — | Docker | 12/12/2014 | 17/6/2026 | Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation. | |
| Modificada | Media (5) | 1.9% | — | DockerDocker-py | 17/11/2014 | 17/6/2026 | Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. | |
| Modificada | Alta (7.2) | 0.39% | — | DockerFedoraproject Fedora | 11/7/2014 | 17/6/2026 | Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.35% | — | Kdocker | 31/12/2004 | 16/6/2026 | kdocker.cpp in kdocker 0.1 through 0.8 does not properly check the ownership of files, which could allow local users to execute arbitrary programs. |