Docker records
115 published records for vendor docker.
Researcher profile
- Entered KEV
- 1 · 0.9%
- Weaponized
- 2 · 1.7%
- Pre-auth RCE
- 8
- With a fix record
- 60%
- Median publish → KEV
- 798 days
Recurring classes
- CWE-20 Improper Input Validation9
- CWE-59 Improper Link Resolution Before File Access ('Link Following')9
- CWE-306 Missing Authentication for Critical Function8
- CWE-264 Permissions, Privileges, and Access Controls7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
115 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2019-15752Weaponized | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exdocker · docker · CWE-732 | High7.8 | KEV | 48.6% | Aug 28, 2019 |
64This week | CVE-2019-5736Weaponized | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | High8.6 | — | 98.5% | Feb 11, 2019 |
45Plan | CVE-2019-14271Proof of concept | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamicaldocker · docker · CWE-665 | Critical9.8 | — | 18.8% | Jul 29, 2019 |
44Plan | CVE-2024-41110Proof of concept | Moby authz zero length regressionmoby · moby · CWE-187 | Critical9.9 | — | 16.5% | Jul 24, 2024 |
42Plan | CVE-2014-9357No exploit | Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in docker · docker · CWE-264 | Critical10.0 | — | 6.2% | Dec 16, 2014 |
41Plan | CVE-2014-0048No exploit | An issue was found in Docker before 1.6.0.docker · docker · CWE-20 | Critical9.8 | — | 6.5% | Jan 2, 2020 |
40Plan | CVE-2020-35184No exploit | The official composer docker images before 1.8.3 contain a blank password for a root user.docker · composer docker image · CWE-306 | Critical9.8 | — | 3.0% | Dec 16, 2020 |
40Plan | CVE-2020-29575No exploit | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user.docker · elixir alpine docker image | Critical9.8 | — | 2.9% | Dec 8, 2020 |
40Plan | CVE-2020-35186No exploit | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user.docker · adminer · CWE-306 | Critical9.8 | — | 2.9% | Dec 16, 2020 |
40Plan | CVE-2020-35185No exploit | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user.docker · ghost alpine docker image · CWE-306 | Critical9.8 | — | 2.9% | Dec 16, 2020 |
40Plan | CVE-2020-29591No exploit | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.docker · registry · CWE-521 | Critical9.8 | — | 2.6% | Dec 11, 2020 |
40Plan | CVE-2020-29580No exploit | The official storm Docker images before 1.2.1 contain a blank password for a root user.docker · storm docker image | Critical9.8 | — | 2.3% | Dec 8, 2020 |
40Plan | CVE-2020-29601No exploit | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user.docker · notary docker image | Critical9.8 | — | 2.3% | Dec 8, 2020 |
40Plan | CVE-2020-29581No exploit | The official spiped docker images before 1.5-alpine contain a blank password for a root user.docker · spiped alpine docker image | Critical9.8 | — | 2.3% | Dec 8, 2020 |
40Plan | CVE-2020-35467No exploit | The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user.docker · docs · CWE-306 | Critical9.8 | — | 2.2% | Dec 15, 2020 |
40Plan | CVE-2020-35195No exploit | The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user.docker · haproxy docker image · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
40Plan | CVE-2020-35196No exploit | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user.docker · rabbitmq docker image · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
40Plan | CVE-2020-35197No exploit | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user.docker · memcached docker image · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
40Plan | CVE-2020-29389No exploit | The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user.docker · crux linux docker image · CWE-306 | Critical9.8 | — | 1.7% | Dec 2, 2020 |
39Monitor | CVE-2015-9259No exploit | In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stdocker · notary · CWE-434 | Critical9.8 | — | 1.3% | Mar 31, 2018 |
39Monitor | CVE-2023-0626No exploit | Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box routedocker · docker desktop · CWE-94 | Critical9.8 | — | 0.9% | Sep 25, 2023 |
39Monitor | CVE-2023-0625No exploit | Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelogdocker · docker desktop · CWE-79 | Critical9.8 | — | 0.9% | Sep 25, 2023 |
36Monitor | CVE-2018-15514No exploit | HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over docker · docker · CWE-502 | High8.8 | — | 2.5% | Aug 31, 2018 |
36Monitor | CVE-2024-8695No exploit | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2docker · desktop · CWE-79 | Critical9.0 | — | 1.3% | Sep 12, 2024 |
35Monitor | CVE-2014-9356No exploit | Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection medocker · docker · CWE-22 | High8.6 | — | 4.9% | Dec 2, 2019 |
- CVE-2019-1575276This week
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex
HighCVSS 7.8KEVWeaponizedEPSS 49%docker · dockerAug 28, 2019
- CVE-2019-573664This week
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
HighCVSS 8.6WeaponizedEPSS 98%docker · dockerFeb 11, 2019
- CVE-2019-1427145Plan
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamical
CriticalCVSS 9.8Proof of conceptEPSS 19%docker · dockerJul 29, 2019
- CVE-2024-4111044Plan
Moby authz zero length regression
CriticalCVSS 9.9Proof of conceptEPSS 16%moby · mobyJul 24, 2024
- CVE-2014-935742Plan
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in
CriticalCVSS 10.0No exploitEPSS 6%docker · dockerDec 16, 2014
- CVE-2014-004841Plan
An issue was found in Docker before 1.6.0.
CriticalCVSS 9.8No exploitEPSS 7%docker · dockerJan 2, 2020
- CVE-2020-3518440Plan
The official composer docker images before 1.8.3 contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · composer docker imageDec 16, 2020
- CVE-2020-2957540Plan
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · elixir alpine docker imageDec 8, 2020
- CVE-2020-3518640Plan
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · adminerDec 16, 2020
- CVE-2020-3518540Plan
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · ghost alpine docker imageDec 16, 2020
- CVE-2020-2959140Plan
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · registryDec 11, 2020
- CVE-2020-2958040Plan
The official storm Docker images before 1.2.1 contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · storm docker imageDec 8, 2020
- CVE-2020-2960140Plan
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · notary docker imageDec 8, 2020
- CVE-2020-2958140Plan
The official spiped docker images before 1.5-alpine contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · spiped alpine docker imageDec 8, 2020
- CVE-2020-3546740Plan
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · docsDec 15, 2020
- CVE-2020-3519540Plan
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · haproxy docker imageDec 16, 2020
- CVE-2020-3519640Plan
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · rabbitmq docker imageDec 16, 2020
- CVE-2020-3519740Plan
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · memcached docker imageDec 16, 2020
- CVE-2020-2938940Plan
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%docker · crux linux docker imageDec 2, 2020
- CVE-2015-925939Monitor
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment st
CriticalCVSS 9.8No exploitEPSS 1%docker · notaryMar 31, 2018
- CVE-2023-062639Monitor
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route
CriticalCVSS 9.8No exploitEPSS 1%docker · docker desktopSep 25, 2023
- CVE-2023-062539Monitor
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog
CriticalCVSS 9.8No exploitEPSS 1%docker · docker desktopSep 25, 2023
- CVE-2018-1551436Monitor
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over
HighCVSS 8.8No exploitEPSS 2%docker · dockerAug 31, 2018
- CVE-2024-869536Monitor
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2
CriticalCVSS 9.0No exploitEPSS 1%docker · desktopSep 12, 2024
- CVE-2014-935635Monitor
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection me
HighCVSS 8.6No exploitEPSS 5%docker · dockerDec 2, 2019