CVE-2013-4311
- EPSS 0.02%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...
CVE-2013-4327
- EPSS 0.03%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec proce...
CVE-2013-1061
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended acce...
CVE-2013-1062
- EPSS 0.05%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUn...
CVE-2013-1063
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitU...
CVE-2013-1064
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
apt-xapian-index before 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSub...
CVE-2013-1065
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a ...
CVE-2013-1066
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnix...
CVE-2013-5745
- EPSS 20.11%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authenticatio...
- EPSS 1.2%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecifie...