Vulnerabilities
Vulnerable Software
Docker:  >> Docker  >> 1.3.2  Security Vulnerabilities
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVSS Score
7.8
EPSS Score
0.001
Published
2016-06-01
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
CVSS Score
3.6
EPSS Score
0.001
Published
2015-05-18
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
CVSS Score
7.2
EPSS Score
0.0
Published
2015-05-18
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
CVSS Score
7.2
EPSS Score
0.001
Published
2015-05-18
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
CVSS Score
6.4
EPSS Score
0.003
Published
2014-12-16
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
CVSS Score
10.0
EPSS Score
0.532
Published
2014-12-16


Contact Us

Shodan ® - All rights reserved