Packagekit Project Packagekit vulnerabilities

4 known vulnerabilities affecting packagekit_project/packagekit.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-0217LOWCVSS 3.3fixed in 1.2.72024-01-03
CVE-2024-0217 [LOW] CWE-416 CVE-2024-0217: A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics f A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered
nvd
CVE-2011-2515MEDIUMCVSS 5.3v0.6.172019-11-27
CVE-2011-2515 [MEDIUM] CWE-732 CVE-2011-2515: PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
nvd
CVE-2018-1106MEDIUMCVSS 5.5fixed in 1.1.102018-04-23
CVE-2018-1106 [MEDIUM] CWE-287 CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without a An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
nvd
CVE-2013-1764LOWCVSS 2.1≤ 0.8.7v0.8.1+5 more2014-04-16
CVE-2013-1764 [LOW] CWE-264 CVE-2013-1764: The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages vi The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
nvd