systemd project records
55 published records for vendor systemd project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 92.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-269 Improper Privilege Management4
- CWE-354 Improper Validation of Integrity Check Value3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
55 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2017-9445No exploit | In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.systemd project · systemd · CWE-787 | High7.5 | — | 54.8% | Jun 28, 2017 |
40Plan | CVE-2015-7510No exploit | Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.systemd project · systemd · CWE-119 | Critical9.8 | — | 4.3% | Sep 25, 2017 |
40Plan | CVE-2017-1000082No exploit | systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.systemd project · systemd · CWE-269 | Critical9.8 | — | 3.9% | Jul 7, 2017 |
40Plan | CVE-2018-21029No exploit | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Critical9.8 | — | 3.1% | Oct 30, 2019 |
39Monitor | CVE-2022-2526No exploit | A use-after-free vulnerability was found in systemd.systemd project · systemd · CWE-416 | Critical9.8 | — | 1.3% | Sep 9, 2022 |
37Monitor | CVE-2017-15908No exploit | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | High7.5 | — | 23.6% | Oct 26, 2017 |
35Monitor | CVE-2017-9217No exploit | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qusystemd project · systemd · CWE-476 | High7.5 | — | 15.3% | May 24, 2017 |
35Monitor | CVE-2018-15688No exploit | Out-of-Bounds write in systemd-networkd dhcpv6 option handlingsystemd project · systemd · CWE-120 | High8.8 | — | 1.7% | Oct 26, 2018 |
32Monitor | CVE-2013-4391No exploit | Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servisystemd project · systemd · CWE-190 | High7.5 | — | 5.4% | Oct 28, 2013 |
32Monitor | CVE-2018-16865No exploit | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | High7.8 | — | 3.0% | Jan 11, 2019 |
32Monitor | CVE-2018-15686Proof of concept | systemd: reexec state injection: fgets() on overlong lines leads to line splittingcanonical · ubuntu linux · CWE-502 | High7.8 | — | 2.3% | Oct 26, 2018 |
31Monitor | CVE-2016-10156Proof of concept | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowisystemd project · systemd · CWE-264 | High7.8 | — | 1.2% | Jan 23, 2017 |
31Monitor | CVE-2017-18078Proof of concept | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinsystemd project · systemd · CWE-59 | High7.8 | — | 1.1% | Jan 29, 2018 |
31Monitor | CVE-2023-26604No exploit | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in whichdebian · debian linux · CWE-269 | High7.8 | — | 1.1% | Mar 3, 2023 |
31Monitor | CVE-2019-3843Proof of concept | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the trsystemd project · systemd · CWE-266 | High7.8 | — | 0.9% | Apr 26, 2019 |
31Monitor | CVE-2019-3844Proof of concept | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichsystemd project · systemd · CWE-268 | High7.8 | — | 0.9% | Apr 26, 2019 |
31Monitor | CVE-2018-16864No exploit | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | High7.8 | — | 0.7% | Jan 11, 2019 |
31Monitor | CVE-2018-6954No exploit | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownesystemd project · systemd · CWE-59 | High7.8 | — | 0.5% | Feb 13, 2018 |
31Monitor | CVE-2020-1712No exploit | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handsystemd project · systemd · CWE-416 | High7.8 | — | 0.5% | Mar 31, 2020 |
29Monitor | CVE-2026-40224No exploit | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.systemd project · systemd · CWE-863 | High7.3 | — | 0.1% | Apr 10, 2026 |
28Monitor | CVE-2019-3842Proof of concept | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variablesystemd project · systemd · CWE-285 | High7.0 | — | 1.2% | Apr 9, 2019 |
28Monitor | CVE-2018-15687Proof of concept | systemd: chown_one() can dereference symlinkscanonical · ubuntu linux · CWE-362 | High7.0 | — | 1.1% | Oct 26, 2018 |
27Monitor | CVE-2013-4327No exploit | systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictiosystemd project · systemd · CWE-362 | Medium6.9 | — | 0.3% | Oct 3, 2013 |
26Monitor | CVE-2020-13776No exploit | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated bysystemd project · systemd · CWE-269 | Medium6.7 | — | 0.5% | Jun 2, 2020 |
25Monitor | CVE-2021-33910No exploit | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupsystemd project · systemd · CWE-770 | Medium5.5 | — | 8.8% | Jul 20, 2021 |
- CVE-2017-944546Plan
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.
HighCVSS 7.5No exploitEPSS 55%systemd project · systemdJun 28, 2017
- CVE-2015-751040Plan
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
CriticalCVSS 9.8No exploitEPSS 4%systemd project · systemdSep 25, 2017
- CVE-2017-100008240Plan
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.
CriticalCVSS 9.8No exploitEPSS 4%systemd project · systemdJul 7, 2017
- CVE-2018-2102940Plan
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
CriticalCVSS 9.8No exploitEPSS 3%systemd project · systemdOct 30, 2019
- CVE-2022-252639Monitor
A use-after-free vulnerability was found in systemd.
CriticalCVSS 9.8No exploitEPSS 1%systemd project · systemdSep 9, 2022
- CVE-2017-1590837Monitor
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
HighCVSS 7.5No exploitEPSS 24%systemd project · systemdOct 26, 2017
- CVE-2017-921735Monitor
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qu
HighCVSS 7.5No exploitEPSS 15%systemd project · systemdMay 24, 2017
- CVE-2018-1568835Monitor
Out-of-Bounds write in systemd-networkd dhcpv6 option handling
HighCVSS 8.8No exploitEPSS 2%systemd project · systemdOct 26, 2018
- CVE-2013-439132Monitor
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servi
HighCVSS 7.5No exploitEPSS 5%systemd project · systemdOct 28, 2013
- CVE-2018-1686532Monitor
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
HighCVSS 7.8No exploitEPSS 3%systemd project · systemdJan 11, 2019
- CVE-2018-1568632Monitor
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
HighCVSS 7.8Proof of conceptEPSS 2%canonical · ubuntu linuxOct 26, 2018
- CVE-2016-1015631Monitor
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowi
HighCVSS 7.8Proof of conceptEPSS 1%systemd project · systemdJan 23, 2017
- CVE-2017-1807831Monitor
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlin
HighCVSS 7.8Proof of conceptEPSS 1%systemd project · systemdJan 29, 2018
- CVE-2023-2660431Monitor
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which
HighCVSS 7.8No exploitEPSS 1%debian · debian linuxMar 3, 2023
- CVE-2019-384331Monitor
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the tr
HighCVSS 7.8Proof of conceptEPSS 1%systemd project · systemdApr 26, 2019
- CVE-2019-384431Monitor
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which
HighCVSS 7.8Proof of conceptEPSS 1%systemd project · systemdApr 26, 2019
- CVE-2018-1686431Monitor
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
HighCVSS 7.8No exploitEPSS 1%systemd project · systemdJan 11, 2019
- CVE-2018-695431Monitor
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain owne
HighCVSS 7.8No exploitEPSS 1%systemd project · systemdFeb 13, 2018
- CVE-2020-171231Monitor
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while hand
HighCVSS 7.8No exploitEPSS 0%systemd project · systemdMar 31, 2020
- CVE-2026-4022429Monitor
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
HighCVSS 7.3No exploitEPSS 0%systemd project · systemdApr 10, 2026
- CVE-2019-384228Monitor
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable
HighCVSS 7.0Proof of conceptEPSS 1%systemd project · systemdApr 9, 2019
- CVE-2018-1568728Monitor
systemd: chown_one() can dereference symlinks
HighCVSS 7.0Proof of conceptEPSS 1%canonical · ubuntu linuxOct 26, 2018
- CVE-2013-432727Monitor
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictio
MediumCVSS 6.9No exploitEPSS 0%systemd project · systemdOct 3, 2013
- CVE-2020-1377626Monitor
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by
MediumCVSS 6.7No exploitEPSS 0%systemd project · systemdJun 2, 2020
- CVE-2021-3391025Monitor
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdup
MediumCVSS 5.5No exploitEPSS 9%systemd project · systemdJul 20, 2021