Skip to main content

Vendor/product archive

freedesktop / dbus CVEs

Beta · best-effort

24 CVEs tagged to freedesktop / dbus0 Critical, 2 High, 10 Medium, 12 Low, 0 Unrated.

CVE-2022-42012

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42011

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42010

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35512

Published Feb 15, 2021

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12049

Published Jun 8, 2020

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file desc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12749

Published Jun 11, 2019

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon),…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0245

Published Feb 13, 2015

D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3637

Published Sep 22, 2014

D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3477

Published Jul 1, 2014

The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohib…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2168

Published Jul 3, 2013

The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2533

Published Jun 22, 2011

The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2200

Published Jun 22, 2011

The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1189

Published Apr 27, 2009

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote at…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4311

Published Dec 10, 2008

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restri…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1