Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Fdiakh

#22117of 56,330
12.2Total CVSS
Vulnerabilities · 2
Low
1
High
1
PT-2026-35169
8.7
2026-04-23
Unknown · Bubblewrap · CVE-2026-41163
**Name of the Vulnerable Software and Affected Versions** bubblewrap versions 0.11.0 through 0.11.1 **Description** A flaw exists in bubblewrap, a low-level unprivileged sandboxing tool, when operating in setuid mode. A local user can use `ptrace` to attach to the process and control the unprivileged portion of the sandbox setup phase. This allows the attacker to bypass intended sandboxing restrictions and execute privileged operations that are normally restricted, specifically the creation of overlay mounts. This could potentially lead to privilege escalation on the system. **Recommendations** Update to version 0.11.2.
PT-2024-26127
3.5
2024-05-14
Sshproxy · Sshproxy · CVE-2024-34713
**Name of the Vulnerable Software and Affected Versions** sshproxy versions prior to 1.6.3 **Description** The issue allows any user authorized to connect to an SSH server using `sshproxy` to inject options to the `ssh` command executed by `sshproxy`. This affects all versions of `sshproxy` prior to 1.6.3. **Recommendations** For versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. As a temporary workaround, consider using the `force command` option in `sshproxy.yaml`, but note that this is rarely relevant.