Show filters
129 Total Results
Displaying 101-110 of 129
Sort by:
Attacker Value
Unknown

CVE-2011-0542

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-0541

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
0
Attacker Value
Unknown

CVE-2011-0543

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
0
Attacker Value
Unknown

CVE-2010-3879

Disclosure Date: January 22, 2011 (last updated October 04, 2023)
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
0
Attacker Value
Unknown

CVE-2010-0789

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
0
Attacker Value
Unknown

CVE-2008-2232

Disclosure Date: July 17, 2008 (last updated October 04, 2023)
The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname.
0
Attacker Value
Unknown

CVE-2008-2284

Disclosure Date: May 18, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-5280

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages.
0
Attacker Value
Unknown

CVE-2007-3705

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm.
0
Attacker Value
Unknown

CVE-2007-3339

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.
0