Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2016-10122
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail does not properly clean environment variables, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2016-10120
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2016-10117
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
0
Attacker Value
Unknown
CVE-2017-5207
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.
0
Attacker Value
Unknown
CVE-2017-5206
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
0
Attacker Value
Unknown
CVE-2017-5940
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180.
0
Attacker Value
Unknown
CVE-2017-5180
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
0
Attacker Value
Unknown
CVE-2016-9016
Disclosure Date: January 19, 2017 (last updated November 25, 2024)
Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
0