Логотип exploitDog
bind:"GHSA-4ch5-gr7v-q6wq" OR bind:"CVE-2021-42762"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-4ch5-gr7v-q6wq" OR bind:"CVE-2021-42762"

Количество 12

Количество 12

github логотип

GHSA-4ch5-gr7v-q6wq

больше 3 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

EPSS: Низкий
ubuntu логотип

CVE-2021-42762

около 4 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-42762

около 4 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-42762

около 4 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-42762

около 4 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allow ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3603-1

около 4 лет назад

Security update for webkit2gtk3

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1454-1

около 4 лет назад

Security update for webkit2gtk3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3768-1

около 4 лет назад

Security update for webkit2gtk3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3603-1

около 4 лет назад

Security update for webkit2gtk3

EPSS: Низкий
fstec логотип

BDU:2024-05804

около 4 лет назад

Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, связанная с небезопасным управлением привилегиями, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20240726-06

больше 1 года назад

Уязвимость webkit2gtk3

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3769-1

около 4 лет назад

Security update for webkit2gtk3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4ch5-gr7v-q6wq

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-42762

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-42762

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-42762

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-42762

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allow ...

CVSS3: 5.3
0%
Низкий
около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3603-1

Security update for webkit2gtk3

0%
Низкий
около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1454-1

Security update for webkit2gtk3

0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3768-1

Security update for webkit2gtk3

0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3603-1

Security update for webkit2gtk3

0%
Низкий
около 4 лет назад
fstec логотип
BDU:2024-05804

Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, связанная с небезопасным управлением привилегиями, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
0%
Низкий
около 4 лет назад
redos логотип
ROS-20240726-06

Уязвимость webkit2gtk3

CVSS3: 5.3
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2021:3769-1

Security update for webkit2gtk3

около 4 лет назад

Уязвимостей на страницу