Vulnerabilidades en moby
38 resultadosAnálisis Vexday
Moby apresenta 38 vulnerabilidades catalogadas, com 3 críticas, mas nenhuma sob ataque ativo no momento. A fraqueza dominante é traversal de diretório (CWE-22), indicando falhas de validação de caminho que podem comprometer a integridade do container. O ritmo recente de 8 divulgações nos últimos 90 dias sugere atividade contínua de descoberta de falhas, exigindo acompanhamento de patches em ambientes de produção.
CVE-2021-32847HIGHMoby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txEPSS 0.4%CVE-2024-32473MEDIUMMoby IPv6 enabled on IPv4-only network interfacesEPSS 0.4%CVE-2021-32846HIGHMoby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txEPSS 0.3%CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2021-41089LOW`docker cp` allows unexpected chmod of host filesEPSS 0.3%CVE-2026-15788MEDIUMWCOW cache mount source selector resolves NTFS junctions outside of cache rootEPSS 0.3%CVE-2024-24557MEDIUMMoby classic builder cache poisoningEPSS 0.3%CVE-2021-32845HIGHMoby HyperKit uninitialized memory use vtrnd pci_vtrnd_notifyEPSS 0.3%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2026-15792MEDIUMPossible panic when incorrect parameters sent from frontendEPSS 0.2%CVE-2021-32844MEDIUMHyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, ` vi_pci_write`EPSS 0.2%CVE-2021-32843MEDIUMHyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has EPSS 0.2%CVE-2025-54388MEDIUMMoby's Firewalld reload makes published container ports accessible from remote hostsEPSS 0.2%CVE-2026-15793MEDIUMGit source checkout from a bundle file could lead to command injectionEPSS 0.2%CVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%CVE-2025-54410LOWMoby's Firewalld reload removes bridge network isolationEPSS 0.2%CVE-2026-41568MEDIUMMoby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swapEPSS 0.1%CVE-2026-42306HIGHMoby: Race condition in docker cp allows bind mount redirection to host pathEPSS 0.1%