Skip to main content

Vendor/product archive

polkit_project / polkit CVEs

Beta · best-effort

11 CVEs tagged to polkit_project / polkit0 Critical, 4 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2021-3560

Published Feb 16, 2022

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be u…

CVSS 7.8 · High
evidence mentions
8
Buzz score
65.5
KEV listedPublic PoC observed

CVE-2019-6133

Published Jan 11, 2019

In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. T…

CVSS 6.7 · Medium

CVE-2015-3256

Published Oct 26, 2015

PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vecto…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3255

Published Oct 26, 2015

The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via dupli…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3218

Published Oct 26, 2015

The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1