VYPR

Vendor CVEs

Systemd Project

All CVEs

66 total · sorted by risk
  • CVE-2022-45873MedNov 23, 2022
    risk 0.00cvss 5.5epss 0.00

    systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put…

  • CVE-2022-3821MedNov 8, 2022
    risk 0.00cvss 5.5epss 0.00

    An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

  • CVE-2022-2526CriSep 9, 2022
    risk 0.00cvss 9.8epss 0.01

    A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks…

  • CVE-2021-3997MedAug 23, 2022
    risk 0.00cvss 5.5epss 0.02

    A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

  • CVE-2020-1712HigMar 31, 2020
    risk 0.00cvss 7.8epss 0.00

    A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate…

  • CVE-2018-21029CriOct 30, 2019
    risk 0.00cvss 9.8epss 0.03

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability…

  • CVE-2018-20839MedMay 17, 2019
    risk 0.00cvss 4.3epss 0.02

    systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.

  • CVE-2012-0871Apr 18, 2014
    risk 0.00cvss epss 0.00

    The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.

  • CVE-2013-4394Oct 28, 2013
    risk 0.00cvss epss 0.00

    The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain…

  • CVE-2013-4393Oct 28, 2013
    risk 0.00cvss epss 0.00

    journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor.

  • CVE-2013-4391Oct 28, 2013
    risk 0.00cvss epss 0.05

    Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.

  • CVE-2013-4327Oct 3, 2013
    risk 0.00cvss epss 0.00

    systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to…

  • CVE-2012-1174Jul 12, 2012
    risk 0.00cvss epss 0.00

    The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session."

  • CVE-2011-0640Jan 25, 2011
    risk 0.00cvss epss 0.00

    The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data…

  • CVE-2010-4176Dec 7, 2010
    risk 0.00cvss epss 0.02

    plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.

  • CVE-2009-1186Apr 17, 2009
    risk 0.00cvss epss 0.01

    Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.

Page 2 of 2