Skip to content
Noroxi

mobyproject records

38 published records for vendor mobyproject.

All records

38 records
  • BuildKit interactive containers API does not validate entitlements check

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    mobyproject · buildkitJan 31, 2024

  • BuildKit vulnerable to malicious frontend causing file escape outside of storage root

    CriticalCVSS 9.8No exploitEPSS 1%

    mobyproject · buildkitMar 26, 2026

  • BuildKit possible host system access from mount stub cleaner

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    mobyproject · buildkitJan 31, 2024

  • moby/moby's dockerd daemon encrypted overlay network may be unauthenticated

    HighCVSS 8.7No exploitEPSS 3%

    mobyproject · mobyApr 4, 2023

  • moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent writ

    HighCVSS 8.1No exploitEPSS 1%

    mobyproject · mobyNov 29, 2024

  • BuildKit Git URL subdir component can cause access to restricted files

    HighCVSS 8.2No exploitEPSS 1%

    mobyproject · buildkitMar 27, 2026

  • Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx

    HighCVSS 7.8No exploitEPSS 0%

    mobyproject · hyperkitFeb 17, 2023

  • Moby classic builder cache poisoning

    HighCVSS 7.8No exploitEPSS 0%

    mobyproject · mobyFeb 1, 2024

  • Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notify

    HighCVSS 7.8No exploitEPSS 0%

    mobyproject · hyperkitFeb 17, 2023

  • An issue was discovered in Docker Moby before 17.06.0.

    HighCVSS 7.5No exploitEPSS 1%

    mobyproject · mobySep 10, 2018

  • External DNS requests from 'internal' networks could lead to data exfiltration

    HighCVSS 7.5No exploitEPSS 1%

    mobyproject · mobyMar 20, 2024

  • BuildKit possible race condition with accessing subpaths from cache mounts

    HighCVSS 7.4No exploitEPSS 1%

    mobyproject · buildkitJan 31, 2024

  • Git source checkout from a bundle file could lead to command injection

    HighCVSS 7.3No exploitEPSS 0%

    mobyproject · buildkitJul 21, 2026

  • Moby: Race condition in docker cp allows bind mount redirection to host path

    HighCVSS 7.2No exploitEPSS 0%

    docker · engineJun 12, 2026

  • moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated

    MediumCVSS 6.8No exploitEPSS 1%

    mobyproject · mobyApr 4, 2023

  • moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted

    MediumCVSS 6.8No exploitEPSS 1%

    mobyproject · mobyApr 4, 2023

  • Malicious client can bypass destination directory validation on local sources upload

    MediumCVSS 6.9No exploitEPSS 0%

    mobyproject · buildkitJul 21, 2026

  • Insufficiently restricted permissions on data directory in Docker Engine

    MediumCVSS 6.3Proof of conceptEPSS 3%

    mobyproject · mobyOct 4, 2021

  • Credentials inlined to Git URLs could end up in provenance attestation in BuildKit

    MediumCVSS 6.5No exploitEPSS 1%

    mobyproject · buildkitMar 6, 2023

  • moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

    MediumCVSS 6.5No exploitEPSS 1%

    mobyproject · mobyNov 29, 2024

  • moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go.

    MediumCVSS 6.5No exploitEPSS 1%

    mobyproject · mobyNov 29, 2024

  • Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx

    MediumCVSS 6.5No exploitEPSS 0%

    mobyproject · hyperkitFeb 20, 2023

  • Moby IPv6 enabled on IPv4-only network interfaces

    MediumCVSS 6.5No exploitEPSS 0%

    mobyproject · mobyApr 18, 2024

  • Moby vulnerability relating to supplementary group permissions

    MediumCVSS 6.3No exploitEPSS 1%

    mobyproject · mobySep 9, 2022

  • `docker cp` allows unexpected chmod of host files

    MediumCVSS 6.3No exploitEPSS 0%

    mobyproject · mobyOct 4, 2021