İçeriğe atla
Noroxi

systemd project kayıtları

systemd project üreticisine ait 55 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%92,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

55 kayıt
  • CVE-2017-9445
    46Planlayın

    In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.

    YüksekCVSS 7,5İstismar yokEPSS %55

    systemd project · systemd28 Haz 2017

  • CVE-2015-7510
    40Planlayın

    Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.

    KritikCVSS 9,8İstismar yokEPSS %4

    systemd project · systemd25 Eyl 2017

  • CVE-2017-1000082
    40Planlayın

    systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.

    KritikCVSS 9,8İstismar yokEPSS %4

    systemd project · systemd7 Tem 2017

  • CVE-2018-21029
    40Planlayın

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.

    KritikCVSS 9,8İstismar yokEPSS %3

    systemd project · systemd30 Eki 2019

  • CVE-2022-2526
    39İzleyin

    A use-after-free vulnerability was found in systemd.

    KritikCVSS 9,8İstismar yokEPSS %1

    systemd project · systemd9 Eyl 2022

  • CVE-2017-15908
    37İzleyin

    In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th

    YüksekCVSS 7,5İstismar yokEPSS %24

    systemd project · systemd26 Eki 2017

  • CVE-2017-9217
    35İzleyin

    systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qu

    YüksekCVSS 7,5İstismar yokEPSS %15

    systemd project · systemd24 May 2017

  • CVE-2018-15688
    35İzleyin

    Out-of-Bounds write in systemd-networkd dhcpv6 option handling

    YüksekCVSS 8,8İstismar yokEPSS %2

    systemd project · systemd26 Eki 2018

  • CVE-2013-4391
    32İzleyin

    Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servi

    YüksekCVSS 7,5İstismar yokEPSS %5

    systemd project · systemd28 Eki 2013

  • CVE-2018-16865
    32İzleyin

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa

    YüksekCVSS 7,8İstismar yokEPSS %3

    systemd project · systemd11 Oca 2019

  • CVE-2018-15686
    32İzleyin

    systemd: reexec state injection: fgets() on overlong lines leads to line splitting

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    canonical · ubuntu linux26 Eki 2018

  • CVE-2016-10156
    31İzleyin

    A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowi

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    systemd project · systemd23 Oca 2017

  • CVE-2017-18078
    31İzleyin

    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlin

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    systemd project · systemd29 Oca 2018

  • CVE-2023-26604
    31İzleyin

    systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which

    YüksekCVSS 7,8İstismar yokEPSS %1

    debian · debian linux3 Mar 2023

  • CVE-2019-3843
    31İzleyin

    It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the tr

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    systemd project · systemd26 Nis 2019

  • CVE-2019-3844
    31İzleyin

    It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    systemd project · systemd26 Nis 2019

  • CVE-2018-16864
    31İzleyin

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa

    YüksekCVSS 7,8İstismar yokEPSS %1

    systemd project · systemd11 Oca 2019

  • CVE-2018-6954
    31İzleyin

    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain owne

    YüksekCVSS 7,8İstismar yokEPSS %1

    systemd project · systemd13 Şub 2018

  • CVE-2020-1712
    31İzleyin

    A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while hand

    YüksekCVSS 7,8İstismar yokEPSS %0

    systemd project · systemd31 Mar 2020

  • CVE-2026-40224
    29İzleyin

    In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

    YüksekCVSS 7,3İstismar yokEPSS %0

    systemd project · systemd10 Nis 2026

  • CVE-2019-3842
    28İzleyin

    In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable

    YüksekCVSS 7,0Kavram kanıtıEPSS %1

    systemd project · systemd9 Nis 2019

  • CVE-2018-15687
    28İzleyin

    systemd: chown_one() can dereference symlinks

    YüksekCVSS 7,0Kavram kanıtıEPSS %1

    canonical · ubuntu linux26 Eki 2018

  • CVE-2013-4327
    27İzleyin

    systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictio

    OrtaCVSS 6,9İstismar yokEPSS %0

    systemd project · systemd3 Eki 2013

  • CVE-2020-13776
    26İzleyin

    systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by

    OrtaCVSS 6,7İstismar yokEPSS %0

    systemd project · systemd2 Haz 2020

  • CVE-2021-33910
    25İzleyin

    basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdup

    OrtaCVSS 5,5İstismar yokEPSS %9

    systemd project · systemd20 Tem 2021