Skip to main content

Vendor archive

deepin CVEs

Beta · best-effort

7 CVEs tagged to vendor deepin2 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-50255

Published Dec 27, 2023

Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50254

Published Dec 22, 2023

Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command e…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13229

Published Jul 4, 2019

deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivile…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13228

Published Jul 4, 2019

deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13227

Published Jul 4, 2019

In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7622

Published Apr 10, 2017

dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the functio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1