Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2016-10122

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail does not properly clean environment variables, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2016-10120

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2016-10117

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
0
Attacker Value
Unknown

CVE-2017-5207

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.
0
Attacker Value
Unknown

CVE-2017-5206

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
0
Attacker Value
Unknown

CVE-2017-5940

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180.
0
Attacker Value
Unknown

CVE-2017-5180

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
0
Attacker Value
Unknown

CVE-2016-9016

Disclosure Date: January 19, 2017 (last updated November 25, 2024)
Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
0