Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): systemd
- Search Type: Search All
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2013-4394 |
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters." Published: October 28, 2013; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 5.9 MEDIUM |
CVE-2013-4393 |
journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor. Published: October 28, 2013; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2013-4392 |
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files. Published: October 28, 2013; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 3.3 LOW |
CVE-2013-4391 |
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow. Published: October 28, 2013; 6:55:03 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2013-4327 |
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. Published: October 03, 2013; 5:55:04 PM -0400 |
V3.x:(not available) V2.0: 6.9 MEDIUM |
CVE-2012-1174 |
The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session." Published: July 12, 2012; 4:55:15 PM -0400 |
V3.x:(not available) V2.0: 3.3 LOW |
CVE-2010-4398 |
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability." Published: December 06, 2010; 8:44:54 AM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2006-1831 |
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php. Published: April 19, 2006; 12:06:00 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |