Vulnerabilities > Mobyproject > Moby > 0.1.5

DATE CVE VULNERABILITY TITLE RISK
2024-02-01 CVE-2024-24557 Origin Validation Error vulnerability in Mobyproject Moby
Moby is an open-source project created by Docker to enable software containerization.
local
low complexity
mobyproject CWE-346
7.8
2022-09-09 CVE-2022-36109 Moby is an open-source project created by Docker to enable software containerization.
network
low complexity
mobyproject fedoraproject
6.3
2022-04-18 CVE-2022-27652 Incorrect Default Permissions vulnerability in multiple products
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions.
4.6
2022-03-24 CVE-2022-24769 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Moby is an open-source project created by Docker to enable and accelerate software containerization.
5.9
2021-10-04 CVE-2021-41089 Improper Preservation of Permissions vulnerability in multiple products
Moby is an open-source project created by Docker to enable software containerization.
local
low complexity
mobyproject fedoraproject CWE-281
6.3
2021-10-04 CVE-2021-41091 Improper Preservation of Permissions vulnerability in multiple products
Moby is an open-source project created by Docker to enable software containerization.
local
low complexity
mobyproject fedoraproject CWE-281
6.3
2018-09-10 CVE-2018-12608 Improper Certificate Validation vulnerability in Mobyproject Moby
An issue was discovered in Docker Moby before 17.06.0.
network
low complexity
mobyproject CWE-295
5.0
2017-11-04 CVE-2017-16539 Information Exposure vulnerability in Mobyproject Moby
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
4.3