VYPR
Vendor

Systemd Project

Products
12
CVEs
66
Across products
86
Status
Private

Products

12

Recent CVEs

66
View all 66 CVEs →
  • CVE-2023-7227CriJan 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.

  • CVE-2017-1000082CriJul 7, 2017
    risk 0.64cvss 9.8epss 0.04

    systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

  • CVE-2015-7510CriSep 25, 2017
    risk 0.57cvss 9.8epss 0.04

    Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.

  • CVE-2019-3844HigApr 26, 2019
    risk 0.54cvss 7.8epss 0.01

    It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access…

  • CVE-2017-18078HigJan 29, 2018
    risk 0.54cvss 7.8epss 0.01

    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for…

  • CVE-2017-9445HigJun 28, 2017
    risk 0.53cvss 7.5epss 0.55

    In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer…

  • CVE-2023-26604HigMar 3, 2023
    risk 0.51cvss 7.8epss 0.01

    systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be…

  • CVE-2018-16865HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.03

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw…

  • CVE-2018-16864HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.01

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate…

  • CVE-2018-6954HigFeb 13, 2018
    risk 0.51cvss 7.8epss 0.01

    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory…

  • CVE-2017-15908HigOct 26, 2017
    risk 0.51cvss 7.5epss 0.24

    In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

  • CVE-2018-15688HigOct 26, 2018
    risk 0.50cvss 8.8epss 0.02

    A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.

  • CVE-2017-9217HigMay 24, 2017
    risk 0.50cvss 7.5epss 0.15

    systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.

  • CVE-2019-3842HigApr 9, 2019
    risk 0.49cvss 7.0epss 0.01

    In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be…

  • CVE-2019-3843HigApr 26, 2019
    risk 0.47cvss 7.8epss 0.01

    It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by…

  • CVE-2018-15686HigOct 26, 2018
    risk 0.47cvss 7.8epss 0.02

    A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd…

  • CVE-2016-10156HigJan 23, 2017
    risk 0.47cvss 7.8epss 0.01

    A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

  • CVE-2026-16742MedAug 10, 2026
    risk 0.44cvss 6.7epss 0.00

    systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

  • CVE-2026-4105MedMar 13, 2026
    risk 0.44cvss 6.7epss 0.00

    A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to…

  • CVE-2020-13776MedJun 3, 2020
    risk 0.44cvss 6.7epss 0.00

    systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for…