VYPR

Libdbus

by Xorg

CVEs (2)

  • CVE-2020-12049MedJun 8, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's…

  • CVE-2012-3524Sep 18, 2012
    risk 0.03cvss epss 0.04

    libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is…