projectatomic records
4 published records for vendor projectatomic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-648 Incorrect Use of Privileged APIs1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-5226No exploit | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to pushprojectatomic · bubblewrap · CWE-20 | Critical10.0 | — | 3.2% | Mar 29, 2017 |
31Monitor | CVE-2020-5291No exploit | Privilege escalation in setuid mode via user namespaces in Bubblewrapprojectatomic · bubblewrap · CWE-648 | High7.8 | — | 0.9% | Mar 31, 2020 |
31Monitor | CVE-2019-12439No exploit | bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point.projectatomic · bubblewrap · CWE-20 | High7.8 | — | 0.6% | May 29, 2019 |
13Monitor | CVE-2016-6349No exploit | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by ruprojectatomic · oci-register-machine · CWE-200 | Low3.3 | — | 0.4% | Mar 29, 2017 |
- CVE-2017-522641Plan
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push
CriticalCVSS 10.0No exploitEPSS 3%projectatomic · bubblewrapMar 29, 2017
- CVE-2020-529131Monitor
Privilege escalation in setuid mode via user namespaces in Bubblewrap
HighCVSS 7.8No exploitEPSS 1%projectatomic · bubblewrapMar 31, 2020
- CVE-2019-1243931Monitor
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point.
HighCVSS 7.8No exploitEPSS 1%projectatomic · bubblewrapMay 29, 2019
- CVE-2016-634913Monitor
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by ru
LowCVSS 3.3No exploitEPSS 0%projectatomic · oci-register-machineMar 29, 2017