cbcvebase.

Debian Dbus vulnerabilities

28 known vulnerabilities affecting debian/dbus.

Total CVEs
28
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM8LOW17

Vulnerabilities

Page 2 of 2
CVE-2013-2168P4LOWCVSS 1.9fixed in dbus 1.6.12-1 (bookworm)2013
CVE-2013-2168 [LOW] CVE-2013-2168: dbus - The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bu... The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message. Scope: local bookworm: resolved (fixed in 1.6.12-1) bullseye: resolved (fixed in 1.6.12-1) forky: resolved (fixed in 1.6.12-1) si
debian
CVE-2014-3637P4LOWCVSS 2.1fixed in dbus 1.8.8-1 (bookworm)2014
CVE-2014-3637 [LOW] CVE-2014-3637: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly... D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor. Scope: local bookworm: resolved (fixed in 1.8.8-1) bullseye: resolved (fixed in 1.8.8-1) forky: resolved (fixed in 1.8
debian
CVE-2014-3639P4LOWCVSS 2.1fixed in dbus 1.8.8-1 (bookworm)2014
CVE-2014-3639 [LOW] CVE-2014-3639: dbus - The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly ... The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections. Scope: local bookworm: resolved (fixed in 1.8.8-1) bullseye: resolved (fixed in 1.8.8-1) forky: resol
debian
CVE-2014-3638P4LOWCVSS 2.1fixed in dbus 1.8.8-1 (bookworm)2014
CVE-2014-3638 [LOW] CVE-2014-3638: dbus - The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.... The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls. Scope: local bookworm: resolved (fixed in 1.8.8-1) bullseye: resolved (fixed in 1.8.8-1) forky: resolved (fixed in 1.8.8-1) sid: resolved (fixed in 1.8.8-1) trixie: r
debian
CVE-2014-3636P4LOWCVSS 1.9fixed in dbus 1.8.8-1 (bookworm)2014
CVE-2014-3636 [LOW] CVE-2014-3636: dbus - D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local user... D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendms
debian
CVE-2010-4352P4LOWCVSS 2.1fixed in dbus 1.2.24-4 (bookworm)2010
CVE-2010-4352 [LOW] CVE-2010-4352: dbus - Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local us... Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants. Scope: local bookworm: resolved (fixed in 1.2.24-4) bullseye: resolved (fixed in 1.2.24-4) forky: resolved (fixed in 1.2.24-4) sid: resolved (fixed in 1.2.24-4) trixie: resolved (fixed in 1.2.24-4)
debian
CVE-2015-0245P4LOWCVSS 1.9fixed in dbus 1.8.16-1 (bookworm)2015
CVE-2015-0245 [LOW] CVE-2015-0245: dbus - D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1... D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds. Scope: local bookworm: resolved (fixe
debian
CVE-2006-6107P4LOWCVSS 1.7fixed in dbus 1.0.2-1 (bookworm)2006
CVE-2006-6107 [LOW] CVE-2006-6107: dbus - Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D... Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages). Scope: local bookworm: resolved (fixed in 1.0.2-1) bullseye: resolved (fixed in 1.0.2-1) forky: resolved (fixed in 1.0.2-1) sid: resolved (fixed in 1.
debian
Debian Dbus vulnerabilities | cvebase