Записи systemd project
55 опубликованных записей вендора systemd project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 92,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-269 Improper Privilege Management4
- CWE-354 Improper Validation of Integrity Check Value3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-20 Improper Input Validation2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
55 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2017-9445Эксплойта нет | In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.systemd project · systemd · CWE-787 | Высокая7,5 | — | 54,8 % | 28 июн. 2017 г. |
40В плане | CVE-2015-7510Эксплойта нет | Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.systemd project · systemd · CWE-119 | Критическая9,8 | — | 4,3 % | 25 сент. 2017 г. |
40В плане | CVE-2017-1000082Эксплойта нет | systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.systemd project · systemd · CWE-269 | Критическая9,8 | — | 3,9 % | 7 июл. 2017 г. |
40В плане | CVE-2018-21029Эксплойта нет | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Критическая9,8 | — | 3,1 % | 30 окт. 2019 г. |
39Наблюдать | CVE-2022-2526Эксплойта нет | A use-after-free vulnerability was found in systemd.systemd project · systemd · CWE-416 | Критическая9,8 | — | 1,3 % | 9 сент. 2022 г. |
37Наблюдать | CVE-2017-15908Эксплойта нет | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | Высокая7,5 | — | 23,6 % | 26 окт. 2017 г. |
35Наблюдать | CVE-2017-9217Эксплойта нет | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qusystemd project · systemd · CWE-476 | Высокая7,5 | — | 15,3 % | 24 мая 2017 г. |
35Наблюдать | CVE-2018-15688Эксплойта нет | Out-of-Bounds write in systemd-networkd dhcpv6 option handlingsystemd project · systemd · CWE-120 | Высокая8,8 | — | 1,7 % | 26 окт. 2018 г. |
32Наблюдать | CVE-2013-4391Эксплойта нет | Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servisystemd project · systemd · CWE-190 | Высокая7,5 | — | 5,4 % | 28 окт. 2013 г. |
32Наблюдать | CVE-2018-16865Эксплойта нет | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | Высокая7,8 | — | 3,0 % | 11 янв. 2019 г. |
32Наблюдать | CVE-2018-15686Proof of concept | systemd: reexec state injection: fgets() on overlong lines leads to line splittingcanonical · ubuntu linux · CWE-502 | Высокая7,8 | — | 2,3 % | 26 окт. 2018 г. |
31Наблюдать | CVE-2016-10156Proof of concept | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowisystemd project · systemd · CWE-264 | Высокая7,8 | — | 1,2 % | 23 янв. 2017 г. |
31Наблюдать | CVE-2017-18078Proof of concept | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinsystemd project · systemd · CWE-59 | Высокая7,8 | — | 1,1 % | 29 янв. 2018 г. |
31Наблюдать | CVE-2023-26604Эксплойта нет | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in whichdebian · debian linux · CWE-269 | Высокая7,8 | — | 1,1 % | 3 мар. 2023 г. |
31Наблюдать | CVE-2019-3843Proof of concept | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the trsystemd project · systemd · CWE-266 | Высокая7,8 | — | 0,9 % | 26 апр. 2019 г. |
31Наблюдать | CVE-2019-3844Proof of concept | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichsystemd project · systemd · CWE-268 | Высокая7,8 | — | 0,9 % | 26 апр. 2019 г. |
31Наблюдать | CVE-2018-16864Эксплойта нет | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | Высокая7,8 | — | 0,7 % | 11 янв. 2019 г. |
31Наблюдать | CVE-2018-6954Эксплойта нет | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownesystemd project · systemd · CWE-59 | Высокая7,8 | — | 0,5 % | 13 февр. 2018 г. |
31Наблюдать | CVE-2020-1712Эксплойта нет | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handsystemd project · systemd · CWE-416 | Высокая7,8 | — | 0,5 % | 31 мар. 2020 г. |
29Наблюдать | CVE-2026-40224Эксплойта нет | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.systemd project · systemd · CWE-863 | Высокая7,3 | — | 0,1 % | 10 апр. 2026 г. |
28Наблюдать | CVE-2019-3842Proof of concept | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variablesystemd project · systemd · CWE-285 | Высокая7,0 | — | 1,2 % | 9 апр. 2019 г. |
28Наблюдать | CVE-2018-15687Proof of concept | systemd: chown_one() can dereference symlinkscanonical · ubuntu linux · CWE-362 | Высокая7,0 | — | 1,1 % | 26 окт. 2018 г. |
27Наблюдать | CVE-2013-4327Эксплойта нет | systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictiosystemd project · systemd · CWE-362 | Средняя6,9 | — | 0,3 % | 3 окт. 2013 г. |
26Наблюдать | CVE-2020-13776Эксплойта нет | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated bysystemd project · systemd · CWE-269 | Средняя6,7 | — | 0,5 % | 2 июн. 2020 г. |
25Наблюдать | CVE-2021-33910Эксплойта нет | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupsystemd project · systemd · CWE-770 | Средняя5,5 | — | 8,8 % | 20 июл. 2021 г. |
- CVE-2017-944546В плане
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.
ВысокаяCVSS 7,5Эксплойта нетEPSS 55 %systemd project · systemd28 июн. 2017 г.
- CVE-2015-751040В плане
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %systemd project · systemd25 сент. 2017 г.
- CVE-2017-100008240В плане
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %systemd project · systemd7 июл. 2017 г.
- CVE-2018-2102940В плане
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %systemd project · systemd30 окт. 2019 г.
- CVE-2022-252639Наблюдать
A use-after-free vulnerability was found in systemd.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %systemd project · systemd9 сент. 2022 г.
- CVE-2017-1590837Наблюдать
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %systemd project · systemd26 окт. 2017 г.
- CVE-2017-921735Наблюдать
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qu
ВысокаяCVSS 7,5Эксплойта нетEPSS 15 %systemd project · systemd24 мая 2017 г.
- CVE-2018-1568835Наблюдать
Out-of-Bounds write in systemd-networkd dhcpv6 option handling
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %systemd project · systemd26 окт. 2018 г.
- CVE-2013-439132Наблюдать
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servi
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %systemd project · systemd28 окт. 2013 г.
- CVE-2018-1686532Наблюдать
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %systemd project · systemd11 янв. 2019 г.
- CVE-2018-1568632Наблюдать
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %canonical · ubuntu linux26 окт. 2018 г.
- CVE-2016-1015631Наблюдать
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowi
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %systemd project · systemd23 янв. 2017 г.
- CVE-2017-1807831Наблюдать
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlin
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %systemd project · systemd29 янв. 2018 г.
- CVE-2023-2660431Наблюдать
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %debian · debian linux3 мар. 2023 г.
- CVE-2019-384331Наблюдать
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the tr
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %systemd project · systemd26 апр. 2019 г.
- CVE-2019-384431Наблюдать
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %systemd project · systemd26 апр. 2019 г.
- CVE-2018-1686431Наблюдать
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %systemd project · systemd11 янв. 2019 г.
- CVE-2018-695431Наблюдать
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain owne
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %systemd project · systemd13 февр. 2018 г.
- CVE-2020-171231Наблюдать
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while hand
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %systemd project · systemd31 мар. 2020 г.
- CVE-2026-4022429Наблюдать
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %systemd project · systemd10 апр. 2026 г.
- CVE-2019-384228Наблюдать
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable
ВысокаяCVSS 7,0Proof of conceptEPSS 1 %systemd project · systemd9 апр. 2019 г.
- CVE-2018-1568728Наблюдать
systemd: chown_one() can dereference symlinks
ВысокаяCVSS 7,0Proof of conceptEPSS 1 %canonical · ubuntu linux26 окт. 2018 г.
- CVE-2013-432727Наблюдать
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictio
СредняяCVSS 6,9Эксплойта нетEPSS 0 %systemd project · systemd3 окт. 2013 г.
- CVE-2020-1377626Наблюдать
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by
СредняяCVSS 6,7Эксплойта нетEPSS 0 %systemd project · systemd2 июн. 2020 г.
- CVE-2021-3391025Наблюдать
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdup
СредняяCVSS 5,5Эксплойта нетEPSS 9 %systemd project · systemd20 июл. 2021 г.