Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ecryptfs

First CVE: Nov 21, 2008Active for: 18 yearsTotal CVEs: 12
16.4
VTI Score
Low

eCryptfs is a stackable Linux encryption filesystem that provides transparent directory-level encryption, with its disclosed vulnerabilities concentrating in the eCryptfs utilities component and centering on improper input validation and privilege-management issues inherent to filesystem-level access control. The vendor occupies a specialized but prominent role in the Linux encryption ecosystem, and defenders managing encrypted storage or home-directory implementations should monitor this component's updates closely. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
4.7
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ecryptfs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2008
17 years ago
Most Recent CVE
Dec 20, 2019
2,408 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-1572HIGH
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesyst
Jan 22, 20168.427NONO
CVE-2012-3409HIGH
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
Dec 20, 20197.825NONO
CVE-2008-5188HIGH
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords
Nov 21, 20087.218NONO
CVE-2011-1836MEDIUM
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrict
Feb 15, 20144.617NONO
CVE-2011-1835MEDIUM
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might
Feb 15, 20144.417NONO
CVE-2011-1831MEDIUM
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new
Feb 15, 20144.617NONO
CVE-2014-9687MEDIUM
eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack.
Mar 16, 20155.015NONO
CVE-2011-1837LOW
The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors.
Feb 15, 20143.615NONO
CVE-2011-1834LOW
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly maintain the mtab file during error conditions, which allows local users to cause a denial of service (
Feb 15, 20142.113NONO
CVE-2011-1832LOW
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to remove directories via a umount system call.
Feb 15, 20142.113NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
33%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (33.3%)
Network0 (0.0%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None4 (33.3%)
Unknown8 (66.7%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None1 (8.3%)
Unknown8 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ecryptfs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ecryptfs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ecryptfs's Products

View all 3 CNAs →

Top CWEs