VYPR

by KDE

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-8422Hig0.547.80.00May 17, 2017KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
CVE-2014-50330.000.00Aug 19, 2014KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."