📦

fuse

Vendor: fuse

Actively Exploited 3 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 6 Remote Access
Total CVEs 237 Total Indexed
Avg. EPSS 13.90% Exploit Prob.
Latest CVE CVE-2026-28369 Mar 27

Security Vulnerability Index

Page 4 / 24
Critical Target
9.8 CVSS
CVE-2015-1427
Exploit Found

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

EPSS: 99.91%
3.3 CVSS

Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

EPSS: 0.33%
3.3 CVSS

fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.

EPSS: 0.32%
3.3 CVSS

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

EPSS: 0.32%
3.3 CVSS

fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.

EPSS: 0.40%
2.1 CVSS

fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.

EPSS: 0.37%
2.1 CVSS
CVE-2005-1858
Exploit Found

FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.

EPSS: 0.76%