projectatomic kayıtları
projectatomic üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-648 Incorrect Use of Privileged APIs1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-5226İstismar yok | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to pushprojectatomic · bubblewrap · CWE-20 | Kritik10,0 | — | %3,2 | 29 Mar 2017 |
31İzleyin | CVE-2020-5291İstismar yok | Privilege escalation in setuid mode via user namespaces in Bubblewrapprojectatomic · bubblewrap · CWE-648 | Yüksek7,8 | — | %0,9 | 31 Mar 2020 |
31İzleyin | CVE-2019-12439İstismar yok | bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point.projectatomic · bubblewrap · CWE-20 | Yüksek7,8 | — | %0,6 | 29 May 2019 |
13İzleyin | CVE-2016-6349İstismar yok | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by ruprojectatomic · oci-register-machine · CWE-200 | Düşük3,3 | — | %0,4 | 29 Mar 2017 |
- CVE-2017-522641Planlayın
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push
KritikCVSS 10,0İstismar yokEPSS %3projectatomic · bubblewrap29 Mar 2017
- CVE-2020-529131İzleyin
Privilege escalation in setuid mode via user namespaces in Bubblewrap
YüksekCVSS 7,8İstismar yokEPSS %1projectatomic · bubblewrap31 Mar 2020
- CVE-2019-1243931İzleyin
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point.
YüksekCVSS 7,8İstismar yokEPSS %1projectatomic · bubblewrap29 May 2019
- CVE-2016-634913İzleyin
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by ru
DüşükCVSS 3,3İstismar yokEPSS %0projectatomic · oci-register-machine29 Mar 2017