Vulnerabilidades em Moby
54 resultadosAnálise Vexday
Moby registra 2 vulnerabilidades na base Vexday, ambas publicadas nos últimos 90 dias, relacionadas principalmente a problemas de autenticação (CWE-290). Nenhuma delas consta em ataques ativos conhecidos (KEV) e não há CVEs críticas registradas, indicando risco moderado e contido no presente momento.
CVE-2024-41110CRITICALMoby authz zero length regressionEPSS 16.5%CVE-2024-23653CRITICALBuildKit interactive containers API does not validate entitlements checkEPSS 3.4%CVE-2021-21285MEDIUMDocker daemon crash during image pull of malicious imageEPSS 3.3%CVE-2021-41091MEDIUMInsufficiently restricted permissions on data directory in Docker EngineEPSS 2.8%CVE-2023-28840HIGHmoby/moby's dockerd daemon encrypted overlay network may be unauthenticatedEPSS 2.6%CVE-2024-23652CRITICALBuildKit possible host system access from mount stub cleanerEPSS 2.5%CVE-2023-28842MEDIUMmoby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedEPSS 1.4%CVE-2024-23650MEDIUMBuildKit possible panic when incorrect parameters sent from frontendEPSS 1.1%CVE-2021-21284MEDIUMprivilege escalation in MobyEPSS 1.1%CVE-2022-36109MEDIUMMoby vulnerability relating to supplementary group permissionsEPSS 1.0%CVE-2023-26054MEDIUMCredentials inlined to Git URLs could end up in provenance attestation in BuildKitEPSS 1.0%CVE-2024-23651HIGHBuildKit possible race condition with accessing subpaths from cache mountsEPSS 0.9%CVE-2026-35469HIGHSpdyStream: DOS on CRIEPSS 0.8%CVE-2024-29018MEDIUMExternal DNS requests from 'internal' networks could lead to data exfiltrationEPSS 0.8%CVE-2023-28841MEDIUMmoby/moby's dockerd daemon encrypted overlay network traffic may be unencryptedEPSS 0.7%CVE-2026-33747HIGHBuildKit vulnerable to malicious frontend causing file escape outside of storage rootEPSS 0.6%CVE-2026-75593HIGHBuildKit: Malicious client can bypass destination directory validation on local sources uploadEPSS 0.5%CVE-2026-33748HIGHBuildKit Git URL subdir component can cause access to restricted filesEPSS 0.5%CVE-2026-33997MEDIUMMoby: Off-by-one error in plugin privilege validationEPSS 0.5%CVE-2022-24769MEDIUMDefault inheritable capabilities for linux container should be emptyEPSS 0.5%