VYPR
Vendor

Accountsservice

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-16743MedJul 24, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files…

  • CVE-2022-1804MedMar 25, 2025
    risk 0.36cvss 5.5epss 0.00

    accountsservice no longer drops permissions when writting .pam_environment

  • CVE-2012-6655LowNov 27, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.