Vulnerabilities
Summary — last 7 days
New vulnerabilities2,807▲ 74 vs. last week
Critical / high1,475▲ 313 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)93▼ 416 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.3) | 0.20% | — | Google Fscrypt | 2/25/2022 | 6/17/2026 | The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the… | |
| Modified | Medium (5.5) | 0.11% | — | Google Fscrypt | 2/25/2022 | 6/17/2026 | The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend… | |
| Modified | Medium (5.5) | 0.13% | — | Google Fscrypt | 2/25/2022 | 6/17/2026 | fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable. | |
| Modified | Medium (6.5) | 0.62% | — | Google Fscrypt | 8/23/2018 | 6/17/2026 | The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam). |