Systemd Project Systemd vulnerabilities

48 known vulnerabilities affecting systemd_project/systemd.

Total CVEs
48
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH17MEDIUM24LOW3

Vulnerabilities

Page 3 of 3
CVE-2016-7796MEDIUMCVSS 5.5v209v213+2 more2016-10-13
CVE-2016-7796 [MEDIUM] CWE-20 CVE-2016-7796: The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service ( The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
nvd
CVE-2016-7795MEDIUMCVSS 5.5≤ 2312016-10-13
CVE-2016-7795 [MEDIUM] CWE-20 CVE-2016-7795: The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.
nvd
CVE-2012-0871MEDIUMCVSS 6.3≤ 037v1+35 more2014-04-18
CVE-2012-0871 [MEDIUM] CWE-59 CVE-2012-0871: The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibl The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
nvd
CVE-2013-4391HIGHCVSS 7.5fixed in 1902013-10-28
CVE-2013-4391 [HIGH] CWE-190 CVE-2013-4391: Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows rem Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
nvd
CVE-2013-4392MEDIUMCVSS 5.0fixed in 2392013-10-28
CVE-2013-4392 [MEDIUM] CWE-59 CVE-2013-4392: systemd, when updating file permissions, allows local users to change the permissions and SELinux se systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
nvd
CVE-2013-4394MEDIUMCVSS 5.9fixed in 1942013-10-28
CVE-2013-4394 [MEDIUM] CWE-276 CVE-2013-4394: The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."
nvd
CVE-2013-4393LOWCVSS 2.1fixed in 1942013-10-28
CVE-2013-4393 [LOW] CVE-2013-4393: journald in systemd, when the origin of native messages is set to file, allows local users to cause journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor.
nvd
CVE-2013-4327MEDIUMCVSS 6.9≤ 2072013-10-03
CVE-2013-4327 [MEDIUM] CVE-2013-4327: systemd does not properly use D-Bus for communication with a polkit authority, which allows local us systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
Systemd Project Systemd vulnerabilities | cvebase