Debian Docker.Io vulnerabilities
58 known vulnerabilities affecting debian/docker.io.
Total CVEs
58
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH15MEDIUM24LOW15
Vulnerabilities
Page 2 of 3
CVE-2020-15157MEDIUMCVSS 6.1fixed in containerd 1.3.2~ds1-2 (bookworm)2020
CVE-2020-15157 [MEDIUM] CVE-2020-15157: containerd - In containerd (an industry-standard container runtime) before version 1.2.14 the...
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL t
debian
CVE-2020-15257MEDIUMCVSS 5.2fixed in containerd 1.4.3~ds1-1 (bookworm)2020
CVE-2020-15257 [MEDIUM] CVE-2020-15257: containerd - containerd is an industry-standard container runtime and is available as a daemo...
containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict
debian
CVE-2020-13401MEDIUMCVSS 6.0fixed in docker.io 19.03.11+dfsg1-1 (bookworm)2020
CVE-2020-13401 [MEDIUM] CVE-2020-13401: docker.io - An issue was discovered in Docker Engine before 19.03.11. An attacker in a conta...
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Scope: local
bookworm: resolved (fixed in 19.03.11+dfsg1-1)
bullseye: resolved (fixed in 19.03.11+dfsg1
debian
CVE-2020-14298LOWCVSS 8.62020
CVE-2020-14298 [HIGH] CVE-2020-14298: docker.io - The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA...
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This i
debian
CVE-2020-14300LOWCVSS 6.42020
CVE-2020-14300 [MEDIUM] CVE-2020-14300: docker.io - The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red...
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously cor
debian
CVE-2020-27534LOWCVSS 5.32020
CVE-2020-27534 [MEDIUM] CVE-2020-27534: docker.io - util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.Op...
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2019-14271CRITICALCVSS 9.8fixed in docker.io 18.09.1+dfsg1-9 (bookworm)2019
CVE-2019-14271 [CRITICAL] CVE-2019-14271: docker.io - In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), c...
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
Scope: local
bookworm: resolved (fixed in 18.09.1+dfsg1-9)
bullseye: resolved (fixed in 18.09.1+dfsg1-9)
forky: resolved (fixed in 18.09.1+dfs
debian
CVE-2019-13139HIGHCVSS 8.4fixed in docker.io 18.09.1+dfsg1-8 (bookworm)2019
CVE-2019-13139 [HIGH] CVE-2019-13139: docker.io - In Docker before 18.09.4, an attacker who is capable of supplying or manipulatin...
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user e
debian
CVE-2019-13509HIGHCVSS 7.5fixed in docker.io 18.09.1+dfsg1-8 (bookworm)2019
CVE-2019-13509 [HIGH] CVE-2019-13509: docker.io - In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 an...
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they
debian
CVE-2019-15752LOWCVSS 7.8KEVPoC2019
CVE-2019-15752 [HIGH] CVE-2019-15752: docker.io - Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privi...
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
Scope: local
bo
debian
CVE-2018-15664HIGHCVSS 7.5fixed in docker.io 18.09.1+dfsg1-7.1 (bookworm)2018
CVE-2018-15664 [HIGH] CVE-2018-15664: docker.io - In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' comma...
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
Scope: local
boo
debian
CVE-2018-12608HIGHCVSS 7.5fixed in docker.io 18.03.1+dfsg1-2 (bookworm)2018
CVE-2018-12608 [HIGH] CVE-2018-12608: docker.io - An issue was discovered in Docker Moby before 17.06.0. The Docker engine validat...
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate)
debian
CVE-2018-10892MEDIUMCVSS 5.3fixed in docker.io 18.06.1+dfsg1-1 (bookworm)2018
CVE-2018-10892 [MEDIUM] CVE-2018-10892: docker.io - The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 t...
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
Scope: local
bookworm: resolved (fixed in 18.06.1+dfsg1-1)
bullseye: resolved (fixed in 18.06.1+dfsg1-1)
fork
debian
CVE-2018-20699LOWCVSS 4.9fixed in docker.io 18.09.1+dfsg1-2 (bookworm)2018
CVE-2018-20699 [MEDIUM] CVE-2018-20699: docker.io - Docker Engine before 18.09 allows attackers to cause a denial of service (docker...
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Scope: local
bookworm: resolved (fixed in 18.09.1+dfsg1-2)
bullseye: resolved (fixed in 18.09.1+dfsg1-2)
forky: r
debian
CVE-2017-14992MEDIUMCVSS 6.5fixed in docker.io 18.03.1+dfsg1-2 (bookworm)2017
CVE-2017-14992 [MEDIUM] CVE-2017-14992: docker.io - Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0...
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.
Scope: local
bookworm: resolved (fixed in 18.03.1+dfsg1-2)
bullseye: resolved (fixed in 18.0
debian
CVE-2017-16539MEDIUMCVSS 5.9fixed in docker.io 1.13.1~ds3-1 (bookworm)2017
CVE-2017-16539 [MEDIUM] CVE-2017-16539: docker.io - The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-...
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
Scope: local
bookworm: resolved (fix
debian
CVE-2016-9962MEDIUMCVSS 6.4fixed in docker.io 1.13.1~ds1-2 (bookworm)2016
CVE-2016-9962 [MEDIUM] CVE-2016-9962: docker.io - RunC allowed additional container processes via 'runc exec' to be ptraced by the...
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside th
debian
CVE-2016-3697LOWCVSS 7.8fixed in runc 0.1.0+dfsg-1 (bookworm)2016
CVE-2016-3697 [HIGH] CVE-2016-3697: docker.io - libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2,...
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2016-8867LOWCVSS 7.52016
CVE-2016-8867 [HIGH] CVE-2016-8867: docker.io - Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability ...
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2016-6595LOWCVSS 6.52016
CVE-2016-6595 [MEDIUM] CVE-2016-6595: docker.io - The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to caus...
The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the manager obviously stops being able to accept new no
debian