CVE-2022-31214
- EPSS 0.07%
- Published 09.06.2022 16:15:08
- Last modified 21.11.2024 07:04:08
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linu...
- EPSS 0.05%
- Published 08.02.2021 20:15:13
- Last modified 21.11.2024 05:57:01
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
CVE-2020-17368
- EPSS 4.49%
- Published 11.08.2020 16:15:12
- Last modified 21.11.2024 05:07:57
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
CVE-2020-17367
- EPSS 0.14%
- Published 11.08.2020 16:15:12
- Last modified 21.11.2024 05:07:57
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
CVE-2019-12589
- EPSS 0.08%
- Published 03.06.2019 03:29:00
- Last modified 21.11.2024 04:23:09
In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker.
CVE-2019-12499
- EPSS 1.37%
- Published 31.05.2019 12:29:02
- Last modified 21.11.2024 04:22:58
Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (wit...
CVE-2016-10121
- EPSS 0.03%
- Published 13.04.2017 14:59:01
- Last modified 20.04.2025 01:37:25
Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.
CVE-2016-10123
- EPSS 0.04%
- Published 13.04.2017 14:59:01
- Last modified 20.04.2025 01:37:25
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.
CVE-2016-10122
- EPSS 0.04%
- Published 13.04.2017 14:59:01
- Last modified 20.04.2025 01:37:25
Firejail does not properly clean environment variables, which allows local users to gain privileges.
CVE-2016-10120
- EPSS 0.03%
- Published 13.04.2017 14:59:01
- Last modified 20.04.2025 01:37:25
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.