linuxcontainers records
32 published records for vendor linuxcontainers.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.1%
- Pre-auth RCE
- 0
- With a fix record
- 96.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference4
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2019-5736Weaponized | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | High8.6 | — | 98.5% | Feb 11, 2019 |
39Monitor | CVE-2026-33897No exploit | Incus vulnerable to arbitrary file read and write through pongo templateslinuxcontainers · incus · CWE-1336 | Critical9.9 | — | 0.5% | Mar 26, 2026 |
38Monitor | CVE-2026-33945No exploit | Abitrary file write through systemd-creds optionlinuxcontainers · incus · CWE-22 | Critical9.6 | — | 0.5% | Mar 26, 2026 |
37Monitor | CVE-2016-8649No exploit | lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptlinuxcontainers · lxc · CWE-264 | Critical9.1 | — | 2.8% | May 1, 2017 |
35Monitor | CVE-2026-33898No exploit | Local Incus UI web server vulnerable to nuthentication bypasslinuxcontainers · incus · CWE-287 | High8.8 | — | 0.5% | Mar 26, 2026 |
34Monitor | CVE-2016-10124No exploit | An issue was discovered in Linux Containers (LXC) before 2016-02-22.linuxcontainers · lxc · CWE-284 | High8.6 | — | 1.5% | Jan 9, 2017 |
34Monitor | CVE-2026-23954No exploit | Incus container image templating arbitrary host file read and writelinuxcontainers · incus · CWE-22 | High8.7 | — | 0.8% | Jan 22, 2026 |
34Monitor | CVE-2026-23953No exploit | Incus container environment configuration newline injectionlinuxcontainers · incus · CWE-93 | High8.7 | — | 0.5% | Jan 22, 2026 |
34Monitor | CVE-2025-64507No exploit | Incus vulnerable to local privilege escalation through custom storage volumeslinuxcontainers · incus · CWE-269 | High8.6 | — | 0.2% | Nov 10, 2025 |
32Monitor | CVE-2017-18641No exploit | In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap contlinuxcontainers · lxc · CWE-287 | High8.1 | — | 1.4% | Feb 9, 2020 |
32Monitor | CVE-2015-1340No exploit | chmod race in doUidshiftIntoContainerlinuxcontainers · lxd · CWE-362 | High8.1 | — | 0.9% | Apr 22, 2019 |
28Monitor | CVE-2013-6441No exploit | The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows llinuxcontainers · lxc · CWE-264 | High7.2 | — | 0.5% | Feb 14, 2014 |
28Monitor | CVE-2026-40251No exploit | Incus out-of-bounds panic in snapshot metadata handling allows denial of servicelinuxcontainers · incus · CWE-129 | High7.1 | — | 0.5% | May 6, 2026 |
28Monitor | CVE-2015-1335No exploit | lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attalinuxcontainers · lxc · CWE-59 | High7.2 | — | 0.5% | Oct 1, 2015 |
28Monitor | CVE-2026-40197No exploit | Incus nil-pointer dereference in custom volume import allows denial of servicelinuxcontainers · incus · CWE-476 | High7.1 | — | 0.4% | May 6, 2026 |
28Monitor | CVE-2026-40195No exploit | Incus nil-pointer dereference in storage bucket import allows denial of servicelinuxcontainers · incus · CWE-476 | High7.1 | — | 0.4% | May 6, 2026 |
26Monitor | CVE-2026-41647No exploit | Incus: Nil-Pointer Dereference via S3 Bucket Importlinuxcontainers · incus · CWE-476 | Medium6.5 | — | 0.5% | May 7, 2026 |
26Monitor | CVE-2026-41684No exploit | Incus: Nil Dereferences on Restore via Malformed YAMLlinuxcontainers · incus · CWE-476 | Medium6.5 | — | 0.5% | May 7, 2026 |
26Monitor | CVE-2026-33743No exploit | Incus vulnerable to denial of source through crafted bucket backup filelinuxcontainers · incus · CWE-770 | Medium6.5 | — | 0.4% | Mar 26, 2026 |
22Monitor | CVE-2026-33542No exploit | Incus does not verify combined fingerprint when downloading images from simplestreams serverslinuxcontainers · incus · CWE-295 | Medium5.7 | — | 0.2% | Mar 26, 2026 |
21Monitor | CVE-2026-41648No exploit | Incus: Unbounded YAML Metadata Decode via Parsinglinuxcontainers · incus · CWE-770 | Medium5.3 | — | 0.4% | May 7, 2026 |
21Monitor | CVE-2026-35527No exploit | Incus blind SSRF via image import preflight HEAD requestlinuxcontainers · incus · CWE-918 | Medium5.3 | — | 0.3% | May 5, 2026 |
19Monitor | CVE-2015-1331No exploit | lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.linuxcontainers · lxc · CWE-59 | Medium4.9 | — | 0.5% | Aug 12, 2015 |
18Monitor | CVE-2015-1334No exploit | attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux linuxcontainers · lxc · CWE-17 | Medium4.6 | — | 0.4% | Aug 12, 2015 |
18Monitor | CVE-2026-33711No exploit | Incus vulnerable to local privilege escalation through VM screenshot pathlinuxcontainers · incus · CWE-61 | Medium4.7 | — | 0.2% | Mar 26, 2026 |
- CVE-2019-573664This week
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
HighCVSS 8.6WeaponizedEPSS 98%docker · dockerFeb 11, 2019
- CVE-2026-3389739Monitor
Incus vulnerable to arbitrary file read and write through pongo templates
CriticalCVSS 9.9No exploitEPSS 1%linuxcontainers · incusMar 26, 2026
- CVE-2026-3394538Monitor
Abitrary file write through systemd-creds option
CriticalCVSS 9.6No exploitEPSS 1%linuxcontainers · incusMar 26, 2026
- CVE-2016-864937Monitor
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descript
CriticalCVSS 9.1No exploitEPSS 3%linuxcontainers · lxcMay 1, 2017
- CVE-2026-3389835Monitor
Local Incus UI web server vulnerable to nuthentication bypass
HighCVSS 8.8No exploitEPSS 0%linuxcontainers · incusMar 26, 2026
- CVE-2016-1012434Monitor
An issue was discovered in Linux Containers (LXC) before 2016-02-22.
HighCVSS 8.6No exploitEPSS 2%linuxcontainers · lxcJan 9, 2017
- CVE-2026-2395434Monitor
Incus container image templating arbitrary host file read and write
HighCVSS 8.7No exploitEPSS 1%linuxcontainers · incusJan 22, 2026
- CVE-2026-2395334Monitor
Incus container environment configuration newline injection
HighCVSS 8.7No exploitEPSS 0%linuxcontainers · incusJan 22, 2026
- CVE-2025-6450734Monitor
Incus vulnerable to local privilege escalation through custom storage volumes
HighCVSS 8.6No exploitEPSS 0%linuxcontainers · incusNov 10, 2025
- CVE-2017-1864132Monitor
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap cont
HighCVSS 8.1No exploitEPSS 1%linuxcontainers · lxcFeb 9, 2020
- CVE-2015-134032Monitor
chmod race in doUidshiftIntoContainer
HighCVSS 8.1No exploitEPSS 1%linuxcontainers · lxdApr 22, 2019
- CVE-2013-644128Monitor
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows l
HighCVSS 7.2No exploitEPSS 0%linuxcontainers · lxcFeb 14, 2014
- CVE-2026-4025128Monitor
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
HighCVSS 7.1No exploitEPSS 0%linuxcontainers · incusMay 6, 2026
- CVE-2015-133528Monitor
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink atta
HighCVSS 7.2No exploitEPSS 0%linuxcontainers · lxcOct 1, 2015
- CVE-2026-4019728Monitor
Incus nil-pointer dereference in custom volume import allows denial of service
HighCVSS 7.1No exploitEPSS 0%linuxcontainers · incusMay 6, 2026
- CVE-2026-4019528Monitor
Incus nil-pointer dereference in storage bucket import allows denial of service
HighCVSS 7.1No exploitEPSS 0%linuxcontainers · incusMay 6, 2026
- CVE-2026-4164726Monitor
Incus: Nil-Pointer Dereference via S3 Bucket Import
MediumCVSS 6.5No exploitEPSS 0%linuxcontainers · incusMay 7, 2026
- CVE-2026-4168426Monitor
Incus: Nil Dereferences on Restore via Malformed YAML
MediumCVSS 6.5No exploitEPSS 0%linuxcontainers · incusMay 7, 2026
- CVE-2026-3374326Monitor
Incus vulnerable to denial of source through crafted bucket backup file
MediumCVSS 6.5No exploitEPSS 0%linuxcontainers · incusMar 26, 2026
- CVE-2026-3354222Monitor
Incus does not verify combined fingerprint when downloading images from simplestreams servers
MediumCVSS 5.7No exploitEPSS 0%linuxcontainers · incusMar 26, 2026
- CVE-2026-4164821Monitor
Incus: Unbounded YAML Metadata Decode via Parsing
MediumCVSS 5.3No exploitEPSS 0%linuxcontainers · incusMay 7, 2026
- CVE-2026-3552721Monitor
Incus blind SSRF via image import preflight HEAD request
MediumCVSS 5.3No exploitEPSS 0%linuxcontainers · incusMay 5, 2026
- CVE-2015-133119Monitor
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
MediumCVSS 4.9No exploitEPSS 0%linuxcontainers · lxcAug 12, 2015
- CVE-2015-133418Monitor
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux
MediumCVSS 4.6No exploitEPSS 0%linuxcontainers · lxcAug 12, 2015
- CVE-2026-3371118Monitor
Incus vulnerable to local privilege escalation through VM screenshot path
MediumCVSS 4.7No exploitEPSS 0%linuxcontainers · incusMar 26, 2026