Skip to main content

Vendor archive

projectatomic CVEs

Beta · best-effort

4 CVEs tagged to vendor projectatomic1 Critical, 2 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2019-12439

Published May 29, 2019

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker ma…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5226

Published Mar 29, 2017

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input b…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6349

Published Mar 29, 2017

The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1