Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2022-46996

Disclosure Date: December 14, 2022 (last updated October 08, 2023)
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Attacker Value
Unknown

CVE-2022-40320

Disclosure Date: September 09, 2022 (last updated November 08, 2023)
cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
Attacker Value
Unknown

CVE-2018-19760

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
0
Attacker Value
Unknown

CVE-2018-10906

Disclosure Date: July 24, 2018 (last updated November 08, 2023)
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
0
Attacker Value
Unknown

CVE-2018-14447

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2015-3202

Disclosure Date: July 02, 2015 (last updated October 05, 2023)
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
0
Attacker Value
Unknown

CVE-2010-3879

Disclosure Date: January 22, 2011 (last updated October 04, 2023)
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
0