VYPR

Vendor CVEs

Lxc

All CVEs

56 total · sorted by risk
  • CVE-2015-1342Dec 7, 2015
    risk 0.00cvss —epss 0.00

    LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.

  • CVE-2015-1335Oct 1, 2015
    risk 0.00cvss —epss 0.00

    lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

  • CVE-2015-1334Aug 12, 2015
    risk 0.00cvss —epss 0.00

    attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.

  • CVE-2015-1331Aug 12, 2015
    risk 0.00cvss —epss 0.00

    lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

  • CVE-2014-1425Jan 7, 2015
    risk 0.00cvss —epss 0.00

    cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.

  • CVE-2013-6441Feb 14, 2014
    risk 0.00cvss —epss 0.01

    The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

Page 2 of 2