CVE-2016-7796
- EPSS 0.39%
- Published 13.10.2016 14:59:14
- Last modified 12.04.2025 10:46:40
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled...
CVE-2016-7795
- EPSS 0.16%
- Published 13.10.2016 14:59:13
- Last modified 12.04.2025 10:46:40
The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.
CVE-2012-0871
- EPSS 0.15%
- Published 18.04.2014 14:55:25
- Last modified 12.04.2025 10:46:40
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
CVE-2013-4394
- EPSS 0.11%
- Published 28.10.2013 22:55:03
- Last modified 11.04.2025 00:51:21
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration f...
CVE-2013-4393
- EPSS 0.15%
- Published 28.10.2013 22:55:03
- Last modified 11.04.2025 00:51:21
journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor.
CVE-2013-4392
- EPSS 0.07%
- Published 28.10.2013 22:55:03
- Last modified 09.06.2025 16:15:23
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
CVE-2013-4391
- EPSS 3.7%
- Published 28.10.2013 22:55:03
- Last modified 11.04.2025 00:51:21
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buf...
CVE-2013-4327
- EPSS 0.04%
- Published 03.10.2013 21:55:04
- Last modified 11.04.2025 00:51:21
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec proce...