Записи linuxcontainers
32 опубликованных записей вендора linuxcontainers.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 96,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference4
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
32 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2019-5736Готовый эксплойт | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Высокая8,6 | — | 98,5 % | 11 февр. 2019 г. |
39Наблюдать | CVE-2026-33897Эксплойта нет | Incus vulnerable to arbitrary file read and write through pongo templateslinuxcontainers · incus · CWE-1336 | Критическая9,9 | — | 0,5 % | 26 мар. 2026 г. |
38Наблюдать | CVE-2026-33945Эксплойта нет | Abitrary file write through systemd-creds optionlinuxcontainers · incus · CWE-22 | Критическая9,6 | — | 0,5 % | 26 мар. 2026 г. |
37Наблюдать | CVE-2016-8649Эксплойта нет | lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptlinuxcontainers · lxc · CWE-264 | Критическая9,1 | — | 2,8 % | 1 мая 2017 г. |
35Наблюдать | CVE-2026-33898Эксплойта нет | Local Incus UI web server vulnerable to nuthentication bypasslinuxcontainers · incus · CWE-287 | Высокая8,8 | — | 0,5 % | 26 мар. 2026 г. |
34Наблюдать | CVE-2016-10124Эксплойта нет | An issue was discovered in Linux Containers (LXC) before 2016-02-22.linuxcontainers · lxc · CWE-284 | Высокая8,6 | — | 1,5 % | 9 янв. 2017 г. |
34Наблюдать | CVE-2026-23954Эксплойта нет | Incus container image templating arbitrary host file read and writelinuxcontainers · incus · CWE-22 | Высокая8,7 | — | 0,8 % | 22 янв. 2026 г. |
34Наблюдать | CVE-2026-23953Эксплойта нет | Incus container environment configuration newline injectionlinuxcontainers · incus · CWE-93 | Высокая8,7 | — | 0,5 % | 22 янв. 2026 г. |
34Наблюдать | CVE-2025-64507Эксплойта нет | Incus vulnerable to local privilege escalation through custom storage volumeslinuxcontainers · incus · CWE-269 | Высокая8,6 | — | 0,2 % | 10 нояб. 2025 г. |
32Наблюдать | CVE-2017-18641Эксплойта нет | In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap contlinuxcontainers · lxc · CWE-287 | Высокая8,1 | — | 1,4 % | 9 февр. 2020 г. |
32Наблюдать | CVE-2015-1340Эксплойта нет | chmod race in doUidshiftIntoContainerlinuxcontainers · lxd · CWE-362 | Высокая8,1 | — | 0,9 % | 22 апр. 2019 г. |
28Наблюдать | CVE-2013-6441Эксплойта нет | The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows llinuxcontainers · lxc · CWE-264 | Высокая7,2 | — | 0,5 % | 14 февр. 2014 г. |
28Наблюдать | CVE-2026-40251Эксплойта нет | Incus out-of-bounds panic in snapshot metadata handling allows denial of servicelinuxcontainers · incus · CWE-129 | Высокая7,1 | — | 0,5 % | 6 мая 2026 г. |
28Наблюдать | CVE-2015-1335Эксплойта нет | lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attalinuxcontainers · lxc · CWE-59 | Высокая7,2 | — | 0,5 % | 1 окт. 2015 г. |
28Наблюдать | CVE-2026-40197Эксплойта нет | Incus nil-pointer dereference in custom volume import allows denial of servicelinuxcontainers · incus · CWE-476 | Высокая7,1 | — | 0,4 % | 6 мая 2026 г. |
28Наблюдать | CVE-2026-40195Эксплойта нет | Incus nil-pointer dereference in storage bucket import allows denial of servicelinuxcontainers · incus · CWE-476 | Высокая7,1 | — | 0,4 % | 6 мая 2026 г. |
26Наблюдать | CVE-2026-41647Эксплойта нет | Incus: Nil-Pointer Dereference via S3 Bucket Importlinuxcontainers · incus · CWE-476 | Средняя6,5 | — | 0,5 % | 7 мая 2026 г. |
26Наблюдать | CVE-2026-41684Эксплойта нет | Incus: Nil Dereferences on Restore via Malformed YAMLlinuxcontainers · incus · CWE-476 | Средняя6,5 | — | 0,5 % | 7 мая 2026 г. |
26Наблюдать | CVE-2026-33743Эксплойта нет | Incus vulnerable to denial of source through crafted bucket backup filelinuxcontainers · incus · CWE-770 | Средняя6,5 | — | 0,4 % | 26 мар. 2026 г. |
22Наблюдать | CVE-2026-33542Эксплойта нет | Incus does not verify combined fingerprint when downloading images from simplestreams serverslinuxcontainers · incus · CWE-295 | Средняя5,7 | — | 0,2 % | 26 мар. 2026 г. |
21Наблюдать | CVE-2026-41648Эксплойта нет | Incus: Unbounded YAML Metadata Decode via Parsinglinuxcontainers · incus · CWE-770 | Средняя5,3 | — | 0,4 % | 7 мая 2026 г. |
21Наблюдать | CVE-2026-35527Эксплойта нет | Incus blind SSRF via image import preflight HEAD requestlinuxcontainers · incus · CWE-918 | Средняя5,3 | — | 0,3 % | 5 мая 2026 г. |
19Наблюдать | CVE-2015-1331Эксплойта нет | lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.linuxcontainers · lxc · CWE-59 | Средняя4,9 | — | 0,5 % | 12 авг. 2015 г. |
18Наблюдать | CVE-2015-1334Эксплойта нет | attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux linuxcontainers · lxc · CWE-17 | Средняя4,6 | — | 0,4 % | 12 авг. 2015 г. |
18Наблюдать | CVE-2026-33711Эксплойта нет | Incus vulnerable to local privilege escalation through VM screenshot pathlinuxcontainers · incus · CWE-61 | Средняя4,7 | — | 0,2 % | 26 мар. 2026 г. |
- CVE-2019-573664На этой неделе
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
ВысокаяCVSS 8,6Готовый эксплойтEPSS 98 %docker · docker11 февр. 2019 г.
- CVE-2026-3389739Наблюдать
Incus vulnerable to arbitrary file read and write through pongo templates
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %linuxcontainers · incus26 мар. 2026 г.
- CVE-2026-3394538Наблюдать
Abitrary file write through systemd-creds option
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %linuxcontainers · incus26 мар. 2026 г.
- CVE-2016-864937Наблюдать
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descript
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %linuxcontainers · lxc1 мая 2017 г.
- CVE-2026-3389835Наблюдать
Local Incus UI web server vulnerable to nuthentication bypass
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linuxcontainers · incus26 мар. 2026 г.
- CVE-2016-1012434Наблюдать
An issue was discovered in Linux Containers (LXC) before 2016-02-22.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %linuxcontainers · lxc9 янв. 2017 г.
- CVE-2026-2395434Наблюдать
Incus container image templating arbitrary host file read and write
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %linuxcontainers · incus22 янв. 2026 г.
- CVE-2026-2395334Наблюдать
Incus container environment configuration newline injection
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %linuxcontainers · incus22 янв. 2026 г.
- CVE-2025-6450734Наблюдать
Incus vulnerable to local privilege escalation through custom storage volumes
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %linuxcontainers · incus10 нояб. 2025 г.
- CVE-2017-1864132Наблюдать
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap cont
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %linuxcontainers · lxc9 февр. 2020 г.
- CVE-2015-134032Наблюдать
chmod race in doUidshiftIntoContainer
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %linuxcontainers · lxd22 апр. 2019 г.
- CVE-2013-644128Наблюдать
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows l
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %linuxcontainers · lxc14 февр. 2014 г.
- CVE-2026-4025128Наблюдать
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %linuxcontainers · incus6 мая 2026 г.
- CVE-2015-133528Наблюдать
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink atta
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %linuxcontainers · lxc1 окт. 2015 г.
- CVE-2026-4019728Наблюдать
Incus nil-pointer dereference in custom volume import allows denial of service
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %linuxcontainers · incus6 мая 2026 г.
- CVE-2026-4019528Наблюдать
Incus nil-pointer dereference in storage bucket import allows denial of service
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %linuxcontainers · incus6 мая 2026 г.
- CVE-2026-4164726Наблюдать
Incus: Nil-Pointer Dereference via S3 Bucket Import
СредняяCVSS 6,5Эксплойта нетEPSS 0 %linuxcontainers · incus7 мая 2026 г.
- CVE-2026-4168426Наблюдать
Incus: Nil Dereferences on Restore via Malformed YAML
СредняяCVSS 6,5Эксплойта нетEPSS 0 %linuxcontainers · incus7 мая 2026 г.
- CVE-2026-3374326Наблюдать
Incus vulnerable to denial of source through crafted bucket backup file
СредняяCVSS 6,5Эксплойта нетEPSS 0 %linuxcontainers · incus26 мар. 2026 г.
- CVE-2026-3354222Наблюдать
Incus does not verify combined fingerprint when downloading images from simplestreams servers
СредняяCVSS 5,7Эксплойта нетEPSS 0 %linuxcontainers · incus26 мар. 2026 г.
- CVE-2026-4164821Наблюдать
Incus: Unbounded YAML Metadata Decode via Parsing
СредняяCVSS 5,3Эксплойта нетEPSS 0 %linuxcontainers · incus7 мая 2026 г.
- CVE-2026-3552721Наблюдать
Incus blind SSRF via image import preflight HEAD request
СредняяCVSS 5,3Эксплойта нетEPSS 0 %linuxcontainers · incus5 мая 2026 г.
- CVE-2015-133119Наблюдать
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
СредняяCVSS 4,9Эксплойта нетEPSS 0 %linuxcontainers · lxc12 авг. 2015 г.
- CVE-2015-133418Наблюдать
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux
СредняяCVSS 4,6Эксплойта нетEPSS 0 %linuxcontainers · lxc12 авг. 2015 г.
- CVE-2026-3371118Наблюдать
Incus vulnerable to local privilege escalation through VM screenshot path
СредняяCVSS 4,7Эксплойта нетEPSS 0 %linuxcontainers · incus26 мар. 2026 г.