Записи packagekit project
8 опубликованных записей вендора packagekit project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-287 Improper Authentication1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2026-41651Proof of concept | PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as rootpackagekit project · packagekit · CWE-367 | Высокая8,8 | — | 0,2 % | 22 апр. 2026 г. |
31Наблюдать | CVE-2020-16122Эксплойта нет | Packagekit's apt backend lets user install untrusted local packagespackagekit project · packagekit · CWE-269 | Высокая7,8 | — | 0,3 % | 7 нояб. 2020 г. |
22Наблюдать | CVE-2018-1106Эксплойта нет | An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signepackagekit project · packagekit · CWE-287 | Средняя5,5 | — | 0,4 % | 23 апр. 2018 г. |
21Наблюдать | CVE-2011-2515Эксплойта нет | PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packagpackagekit project · packagekit · CWE-732 | Средняя5,3 | — | 0,4 % | 27 нояб. 2019 г. |
13Наблюдать | CVE-2020-16121Эксплойта нет | PackageKit error messages leak presence and mimetype of files to unprivileged userspackagekit project · packagekit · CWE-209 | Низкая3,3 | — | 0,5 % | 7 нояб. 2020 г. |
13Наблюдать | CVE-2022-0987Эксплойта нет | A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files.packagekit project · packagekit · CWE-200 | Низкая3,3 | — | 0,3 % | 28 июн. 2022 г. |
13Наблюдать | CVE-2024-0217Эксплойта нет | Packagekitd: use-after-free in idle function callbackpackagekit project · packagekit · CWE-416 | Низкая3,3 | — | 0,2 % | 3 янв. 2024 г. |
8Наблюдать | CVE-2013-1764Эксплойта нет | The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.packagekit project · packagekit · CWE-264 | Низкая2,1 | — | 0,4 % | 16 апр. 2014 г. |
- CVE-2026-4165135Наблюдать
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %packagekit project · packagekit22 апр. 2026 г.
- CVE-2020-1612231Наблюдать
Packagekit's apt backend lets user install untrusted local packages
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %packagekit project · packagekit7 нояб. 2020 г.
- CVE-2018-110622Наблюдать
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signe
СредняяCVSS 5,5Эксплойта нетEPSS 0 %packagekit project · packagekit23 апр. 2018 г.
- CVE-2011-251521Наблюдать
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packag
СредняяCVSS 5,3Эксплойта нетEPSS 0 %packagekit project · packagekit27 нояб. 2019 г.
- CVE-2020-1612113Наблюдать
PackageKit error messages leak presence and mimetype of files to unprivileged users
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %packagekit project · packagekit7 нояб. 2020 г.
- CVE-2022-098713Наблюдать
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %packagekit project · packagekit28 июн. 2022 г.
- CVE-2024-021713Наблюдать
Packagekitd: use-after-free in idle function callback
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %packagekit project · packagekit3 янв. 2024 г.
- CVE-2013-17648Наблюдать
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %packagekit project · packagekit16 апр. 2014 г.