cbcvebase.

Debian Systemd vulnerabilities

50 known vulnerabilities affecting debian/systemd.

Total CVEs
50
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM17LOW13

Vulnerabilities

Page 3 of 3
CVE-2019-15718P4MEDIUMCVSS 4.4fixed in systemd 242-7 (bookworm)2019
CVE-2019-15718 [MEDIUM] CVE-2019-15718: systemd - In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c... In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to chan
debian
CVE-2018-16888P4LOWCVSS 4.7fixed in systemd 237-1 (bookworm)2018
CVE-2018-16888 [MEDIUM] CVE-2018-16888: systemd - It was discovered systemd does not correctly check the content of PIDFile files ... It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged p
debian
CVE-2016-7796P4MEDIUMCVSS 5.5fixed in systemd 231-9 (bookworm)2016
CVE-2016-7796 [MEDIUM] CVE-2016-7796: systemd - The manager_dispatch_notify_fd function in systemd allows local users to cause a... The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled. Scope: local bookworm: resolved (fixed in 231-9) bullseye: resolved (fixed in 231-9) forky: resolved (fixed in 231-9
debian
CVE-2016-7795P4MEDIUMCVSS 5.5fixed in systemd 231-9 (bookworm)2016
CVE-2016-7795 [MEDIUM] CVE-2016-7795: systemd - The manager_invoke_notify_message function in systemd 231 and earlier allows loc... The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket. Scope: local bookworm: resolved (fixed in 231-9) bullseye: resolved (fixed in 231-9) forky: resolved (fixed in 231-9) sid: resolved (fixed in 231-9) trixie: r
debian
CVE-2018-16866P4LOWCVSS 3.3fixed in systemd 240-1 (bookworm)2018
CVE-2018-16866 [LOW] CVE-2018-16866: systemd - An out of bounds read was discovered in systemd-journald in the way it parses lo... An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable. Scope: local bookworm: resolved (fixed in 240-1) bullseye: resolved (fixed in 240-1) forky: resolved (fixed in 240-1) sid: resolved (f
debian
CVE-2012-1174P4LOWCVSS 3.3fixed in systemd 44-1 (bookworm)2012
CVE-2012-1174 [LOW] CVE-2012-1174: systemd - The rm_rf_children function in util.c in the systemd-logind login manager in sys... The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session." Scope: local bookworm: resolved (fixed in 44-1) bullseye: resolved (fixed in 44-1) forky: resolved (fixed in 4
debian
CVE-2014-9770P4LOWCVSS 3.3fixed in systemd 215-1 (bookworm)2014
CVE-2014-9770 [LOW] CVE-2014-9770: systemd - tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal ... tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive information by reading these files. Scope: local bookworm: resolved (fixed in 215-1) bullseye: resolved (fixed in 215-1) forky: resolved (fixed in 215-1) sid: resolved (fixed in 215
debian
CVE-2015-8842P4LOWCVSS 3.3fixed in systemd 215-1 (bookworm)2015
CVE-2015-8842 [LOW] CVE-2015-8842: systemd - tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log... tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file. Scope: local bookworm: resolved (fixed in 215-1) bullseye: resolved (fixed in 215-1) forky: resolved (fixed in 215-1) sid: resolved (fixed in 215-1) trixie: resolved (fixed in 215-1)
debian
CVE-2013-4393P4LOWCVSS 2.1fixed in systemd 204-5 (bookworm)2013
CVE-2013-4393 [LOW] CVE-2013-4393: systemd - journald in systemd, when the origin of native messages is set to file, allows l... journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor. Scope: local bookworm: resolved (fixed in 204-5) bullseye: resolved (fixed in 204-5) forky: resolved (fixed in 204-5) sid: resolved (fixed in 204-5) trixie: resolved (fixed in 204-5)
debian
CVE-2019-20386P4LOWCVSS 2.4fixed in systemd 243-5 (bookworm)2019
CVE-2019-20386 [LOW] CVE-2019-20386: systemd - An issue was discovered in button_open in login/logind-button.c in systemd befor... An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur. Scope: local bookworm: resolved (fixed in 243-5) bullseye: resolved (fixed in 243-5) forky: resolved (fixed in 243-5) sid: resolved (fixed in 243-5) trixie: resolved (fixed in 243-5)
debian
Debian Systemd vulnerabilities | cvebase