Loading HuntDB...

Docker Inc.

1 Product 10 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
6
Medium
3
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

CVE-2024-6222 UNKNOWN 1 year ago

In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the h…

CVE-2024-5652 MEDIUM 1 year ago

In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker…

CVE-2023-0633 HIGH 1 year, 10 months ago

In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docke…

CVE-2023-0627 MEDIUM 1 year, 10 months ago

Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This is…

CVE-2023-0626 HIGH 1 year, 10 months ago

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

CVE-2023-0625 HIGH 1 year, 10 months ago

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0…

CVE-2023-5166 HIGH 1 year, 10 months ago

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

CVE-2023-5165 HIGH 1 year, 10 months ago

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains …

CVE-2023-0629 HIGH 2 years, 4 months ago

Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to dock…

CVE-2023-0628 MEDIUM 2 years, 4 months ago

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking…