mobyproject kayıtları
mobyproject üreticisine ait 38 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %84,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-476 NULL Pointer Dereference3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-863 Incorrect Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-281 Improper Preservation of Permissions2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
38 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-23653Kavram kanıtı | BuildKit interactive containers API does not validate entitlements checkmobyproject · buildkit · CWE-863 | Kritik9,8 | — | %3,4 | 31 Oca 2024 |
39İzleyin | CVE-2026-33747İstismar yok | BuildKit vulnerable to malicious frontend causing file escape outside of storage rootmobyproject · buildkit · CWE-22 | Kritik9,8 | — | %0,6 | 26 Mar 2026 |
37İzleyin | CVE-2024-23652Kavram kanıtı | BuildKit possible host system access from mount stub cleanermobyproject · buildkit · CWE-22 | Kritik9,1 | — | %2,5 | 31 Oca 2024 |
35İzleyin | CVE-2023-28840İstismar yok | moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmobyproject · moby · CWE-420 | Yüksek8,7 | — | %2,6 | 4 Nis 2023 |
32İzleyin | CVE-2024-36623İstismar yok | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent writmobyproject · moby · CWE-362 | Yüksek8,1 | — | %0,6 | 29 Kas 2024 |
32İzleyin | CVE-2026-33748İstismar yok | BuildKit Git URL subdir component can cause access to restricted filesmobyproject · buildkit · CWE-22 | Yüksek8,2 | — | %0,5 | 27 Mar 2026 |
31İzleyin | CVE-2021-32846İstismar yok | Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmobyproject · hyperkit · CWE-908 | Yüksek7,8 | — | %0,3 | 17 Şub 2023 |
31İzleyin | CVE-2024-24557İstismar yok | Moby classic builder cache poisoningmobyproject · moby · CWE-345 | Yüksek7,8 | — | %0,3 | 1 Şub 2024 |
31İzleyin | CVE-2021-32845İstismar yok | Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notifymobyproject · hyperkit · CWE-908 | Yüksek7,8 | — | %0,3 | 17 Şub 2023 |
30İzleyin | CVE-2018-12608İstismar yok | An issue was discovered in Docker Moby before 17.06.0.mobyproject · moby · CWE-295 | Yüksek7,5 | — | %0,9 | 10 Eyl 2018 |
30İzleyin | CVE-2024-29018İstismar yok | External DNS requests from 'internal' networks could lead to data exfiltrationmobyproject · moby · CWE-669 | Yüksek7,5 | — | %0,8 | 20 Mar 2024 |
29İzleyin | CVE-2024-23651İstismar yok | BuildKit possible race condition with accessing subpaths from cache mountsmobyproject · buildkit · CWE-362 | Yüksek7,4 | — | %0,9 | 31 Oca 2024 |
29İzleyin | CVE-2026-15793İstismar yok | Git source checkout from a bundle file could lead to command injectionmobyproject · buildkit · CWE-88 | Yüksek7,3 | — | %0,3 | 21 Tem 2026 |
28İzleyin | CVE-2026-42306İstismar yok | Moby: Race condition in docker cp allows bind mount redirection to host pathdocker · engine · CWE-61 | Yüksek7,2 | — | %0,1 | 12 Haz 2026 |
27İzleyin | CVE-2023-28842İstismar yok | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmobyproject · moby · CWE-420 | Orta6,8 | — | %1,4 | 4 Nis 2023 |
27İzleyin | CVE-2023-28841İstismar yok | moby/moby's dockerd daemon encrypted overlay network traffic may be unencryptedmobyproject · moby · CWE-311 | Orta6,8 | — | %0,7 | 4 Nis 2023 |
27İzleyin | CVE-2026-15789İstismar yok | Malicious client can bypass destination directory validation on local sources uploadmobyproject · buildkit · CWE-22 | Orta6,9 | — | %0,3 | 21 Tem 2026 |
26İzleyin | CVE-2021-41091Kavram kanıtı | Insufficiently restricted permissions on data directory in Docker Enginemobyproject · moby · CWE-281 | Orta6,3 | — | %2,8 | 4 Eki 2021 |
26İzleyin | CVE-2023-26054İstismar yok | Credentials inlined to Git URLs could end up in provenance attestation in BuildKitmobyproject · buildkit · CWE-200 | Orta6,5 | — | %1,0 | 6 Mar 2023 |
26İzleyin | CVE-2024-36620İstismar yok | moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.mobyproject · moby · CWE-476 | Orta6,5 | — | %0,8 | 29 Kas 2024 |
26İzleyin | CVE-2024-36621İstismar yok | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go.mobyproject · moby · CWE-362 | Orta6,5 | — | %0,6 | 29 Kas 2024 |
26İzleyin | CVE-2021-32847İstismar yok | Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmobyproject · hyperkit · CWE-125 | Orta6,5 | — | %0,4 | 20 Şub 2023 |
26İzleyin | CVE-2024-32473İstismar yok | Moby IPv6 enabled on IPv4-only network interfacesmobyproject · moby · CWE-668 | Orta6,5 | — | %0,4 | 18 Nis 2024 |
25İzleyin | CVE-2022-36109İstismar yok | Moby vulnerability relating to supplementary group permissionsmobyproject · moby · CWE-863 | Orta6,3 | — | %1,0 | 9 Eyl 2022 |
25İzleyin | CVE-2021-41089İstismar yok | `docker cp` allows unexpected chmod of host filesmobyproject · moby · CWE-281 | Orta6,3 | — | %0,3 | 4 Eki 2021 |
- CVE-2024-2365340Planlayın
BuildKit interactive containers API does not validate entitlements check
KritikCVSS 9,8Kavram kanıtıEPSS %3mobyproject · buildkit31 Oca 2024
- CVE-2026-3374739İzleyin
BuildKit vulnerable to malicious frontend causing file escape outside of storage root
KritikCVSS 9,8İstismar yokEPSS %1mobyproject · buildkit26 Mar 2026
- CVE-2024-2365237İzleyin
BuildKit possible host system access from mount stub cleaner
KritikCVSS 9,1Kavram kanıtıEPSS %2mobyproject · buildkit31 Oca 2024
- CVE-2023-2884035İzleyin
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
YüksekCVSS 8,7İstismar yokEPSS %3mobyproject · moby4 Nis 2023
- CVE-2024-3662332İzleyin
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent writ
YüksekCVSS 8,1İstismar yokEPSS %1mobyproject · moby29 Kas 2024
- CVE-2026-3374832İzleyin
BuildKit Git URL subdir component can cause access to restricted files
YüksekCVSS 8,2İstismar yokEPSS %1mobyproject · buildkit27 Mar 2026
- CVE-2021-3284631İzleyin
Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx
YüksekCVSS 7,8İstismar yokEPSS %0mobyproject · hyperkit17 Şub 2023
- CVE-2024-2455731İzleyin
Moby classic builder cache poisoning
YüksekCVSS 7,8İstismar yokEPSS %0mobyproject · moby1 Şub 2024
- CVE-2021-3284531İzleyin
Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notify
YüksekCVSS 7,8İstismar yokEPSS %0mobyproject · hyperkit17 Şub 2023
- CVE-2018-1260830İzleyin
An issue was discovered in Docker Moby before 17.06.0.
YüksekCVSS 7,5İstismar yokEPSS %1mobyproject · moby10 Eyl 2018
- CVE-2024-2901830İzleyin
External DNS requests from 'internal' networks could lead to data exfiltration
YüksekCVSS 7,5İstismar yokEPSS %1mobyproject · moby20 Mar 2024
- CVE-2024-2365129İzleyin
BuildKit possible race condition with accessing subpaths from cache mounts
YüksekCVSS 7,4İstismar yokEPSS %1mobyproject · buildkit31 Oca 2024
- CVE-2026-1579329İzleyin
Git source checkout from a bundle file could lead to command injection
YüksekCVSS 7,3İstismar yokEPSS %0mobyproject · buildkit21 Tem 2026
- CVE-2026-4230628İzleyin
Moby: Race condition in docker cp allows bind mount redirection to host path
YüksekCVSS 7,2İstismar yokEPSS %0docker · engine12 Haz 2026
- CVE-2023-2884227İzleyin
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
OrtaCVSS 6,8İstismar yokEPSS %1mobyproject · moby4 Nis 2023
- CVE-2023-2884127İzleyin
moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted
OrtaCVSS 6,8İstismar yokEPSS %1mobyproject · moby4 Nis 2023
- CVE-2026-1578927İzleyin
Malicious client can bypass destination directory validation on local sources upload
OrtaCVSS 6,9İstismar yokEPSS %0mobyproject · buildkit21 Tem 2026
- CVE-2021-4109126İzleyin
Insufficiently restricted permissions on data directory in Docker Engine
OrtaCVSS 6,3Kavram kanıtıEPSS %3mobyproject · moby4 Eki 2021
- CVE-2023-2605426İzleyin
Credentials inlined to Git URLs could end up in provenance attestation in BuildKit
OrtaCVSS 6,5İstismar yokEPSS %1mobyproject · buildkit6 Mar 2023
- CVE-2024-3662026İzleyin
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
OrtaCVSS 6,5İstismar yokEPSS %1mobyproject · moby29 Kas 2024
- CVE-2024-3662126İzleyin
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go.
OrtaCVSS 6,5İstismar yokEPSS %1mobyproject · moby29 Kas 2024
- CVE-2021-3284726İzleyin
Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx
OrtaCVSS 6,5İstismar yokEPSS %0mobyproject · hyperkit20 Şub 2023
- CVE-2024-3247326İzleyin
Moby IPv6 enabled on IPv4-only network interfaces
OrtaCVSS 6,5İstismar yokEPSS %0mobyproject · moby18 Nis 2024
- CVE-2022-3610925İzleyin
Moby vulnerability relating to supplementary group permissions
OrtaCVSS 6,3İstismar yokEPSS %1mobyproject · moby9 Eyl 2022
- CVE-2021-4108925İzleyin
`docker cp` allows unexpected chmod of host files
OrtaCVSS 6,3İstismar yokEPSS %0mobyproject · moby4 Eki 2021