Skip to content
Noroxi

linuxcontainers records

32 published records for vendor linuxcontainers.

All records

32 records
  • CVE-2019-5736
    64This week

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen

    HighCVSS 8.6WeaponizedEPSS 98%

    docker · dockerFeb 11, 2019

  • Incus vulnerable to arbitrary file read and write through pongo templates

    CriticalCVSS 9.9No exploitEPSS 1%

    linuxcontainers · incusMar 26, 2026

  • Abitrary file write through systemd-creds option

    CriticalCVSS 9.6No exploitEPSS 1%

    linuxcontainers · incusMar 26, 2026

  • CVE-2016-8649
    37Monitor

    lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descript

    CriticalCVSS 9.1No exploitEPSS 3%

    linuxcontainers · lxcMay 1, 2017

  • Local Incus UI web server vulnerable to nuthentication bypass

    HighCVSS 8.8No exploitEPSS 0%

    linuxcontainers · incusMar 26, 2026

  • An issue was discovered in Linux Containers (LXC) before 2016-02-22.

    HighCVSS 8.6No exploitEPSS 2%

    linuxcontainers · lxcJan 9, 2017

  • Incus container image templating arbitrary host file read and write

    HighCVSS 8.7No exploitEPSS 1%

    linuxcontainers · incusJan 22, 2026

  • Incus container environment configuration newline injection

    HighCVSS 8.7No exploitEPSS 0%

    linuxcontainers · incusJan 22, 2026

  • Incus vulnerable to local privilege escalation through custom storage volumes

    HighCVSS 8.6No exploitEPSS 0%

    linuxcontainers · incusNov 10, 2025

  • In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap cont

    HighCVSS 8.1No exploitEPSS 1%

    linuxcontainers · lxcFeb 9, 2020

  • CVE-2015-1340
    32Monitor

    chmod race in doUidshiftIntoContainer

    HighCVSS 8.1No exploitEPSS 1%

    linuxcontainers · lxdApr 22, 2019

  • CVE-2013-6441
    28Monitor

    The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows l

    HighCVSS 7.2No exploitEPSS 0%

    linuxcontainers · lxcFeb 14, 2014

  • Incus out-of-bounds panic in snapshot metadata handling allows denial of service

    HighCVSS 7.1No exploitEPSS 0%

    linuxcontainers · incusMay 6, 2026

  • CVE-2015-1335
    28Monitor

    lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink atta

    HighCVSS 7.2No exploitEPSS 0%

    linuxcontainers · lxcOct 1, 2015

  • Incus nil-pointer dereference in custom volume import allows denial of service

    HighCVSS 7.1No exploitEPSS 0%

    linuxcontainers · incusMay 6, 2026

  • Incus nil-pointer dereference in storage bucket import allows denial of service

    HighCVSS 7.1No exploitEPSS 0%

    linuxcontainers · incusMay 6, 2026

  • Incus: Nil-Pointer Dereference via S3 Bucket Import

    MediumCVSS 6.5No exploitEPSS 0%

    linuxcontainers · incusMay 7, 2026

  • Incus: Nil Dereferences on Restore via Malformed YAML

    MediumCVSS 6.5No exploitEPSS 0%

    linuxcontainers · incusMay 7, 2026

  • Incus vulnerable to denial of source through crafted bucket backup file

    MediumCVSS 6.5No exploitEPSS 0%

    linuxcontainers · incusMar 26, 2026

  • Incus does not verify combined fingerprint when downloading images from simplestreams servers

    MediumCVSS 5.7No exploitEPSS 0%

    linuxcontainers · incusMar 26, 2026

  • Incus: Unbounded YAML Metadata Decode via Parsing

    MediumCVSS 5.3No exploitEPSS 0%

    linuxcontainers · incusMay 7, 2026

  • Incus blind SSRF via image import preflight HEAD request

    MediumCVSS 5.3No exploitEPSS 0%

    linuxcontainers · incusMay 5, 2026

  • CVE-2015-1331
    19Monitor

    lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

    MediumCVSS 4.9No exploitEPSS 0%

    linuxcontainers · lxcAug 12, 2015

  • CVE-2015-1334
    18Monitor

    attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux

    MediumCVSS 4.6No exploitEPSS 0%

    linuxcontainers · lxcAug 12, 2015

  • Incus vulnerable to local privilege escalation through VM screenshot path

    MediumCVSS 4.7No exploitEPSS 0%

    linuxcontainers · incusMar 26, 2026