Docker Desktop 2.2.0.4

CPE Details

Docker Desktop 2.2.0.4
2.2.0.4
2020-06-09
09h57 +00:00
2020-06-09
09h57 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:docker:docker_desktop:2.2.0.4:*:*:*:*:*:*:*

Informations

Vendor

docker

Product

docker_desktop

Version

2.2.0.4

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-0633 2023-09-25 15h32 +00:00 In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.
7.8
Haute
CVE-2023-0626 2023-09-25 15h31 +00:00 Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.
9.8
Critique
CVE-2023-0625 2023-09-25 15h31 +00:00 Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
9.8
Critique
CVE-2023-5166 2023-09-25 15h30 +00:00 Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.
8
Haute
CVE-2023-0628 2023-03-13 11h16 +00:00 Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
7.8
Haute
CVE-2021-44719 2022-05-25 13h31 +00:00 Docker Desktop 4.3.0 has Incorrect Access Control.
8.4
Haute
CVE-2022-26659 2022-03-25 19h50 +00:00 Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
7.1
Haute
CVE-2022-23774 2022-02-01 04h30 +00:00 Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
5.3
Moyen
CVE-2020-11492 2020-06-05 11h10 +00:00 An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.
7.8
Haute