systemd project kayıtları
systemd project üreticisine ait 55 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %92,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-269 Improper Privilege Management4
- CWE-354 Improper Validation of Integrity Check Value3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
55 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2017-9445İstismar yok | In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.systemd project · systemd · CWE-787 | Yüksek7,5 | — | %54,8 | 28 Haz 2017 |
40Planlayın | CVE-2015-7510İstismar yok | Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.systemd project · systemd · CWE-119 | Kritik9,8 | — | %4,3 | 25 Eyl 2017 |
40Planlayın | CVE-2017-1000082İstismar yok | systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.systemd project · systemd · CWE-269 | Kritik9,8 | — | %3,9 | 7 Tem 2017 |
40Planlayın | CVE-2018-21029İstismar yok | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Kritik9,8 | — | %3,1 | 30 Eki 2019 |
39İzleyin | CVE-2022-2526İstismar yok | A use-after-free vulnerability was found in systemd.systemd project · systemd · CWE-416 | Kritik9,8 | — | %1,3 | 9 Eyl 2022 |
37İzleyin | CVE-2017-15908İstismar yok | In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in thsystemd project · systemd · CWE-835 | Yüksek7,5 | — | %23,6 | 26 Eki 2017 |
35İzleyin | CVE-2017-9217İstismar yok | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qusystemd project · systemd · CWE-476 | Yüksek7,5 | — | %15,3 | 24 May 2017 |
35İzleyin | CVE-2018-15688İstismar yok | Out-of-Bounds write in systemd-networkd dhcpv6 option handlingsystemd project · systemd · CWE-120 | Yüksek8,8 | — | %1,7 | 26 Eki 2018 |
32İzleyin | CVE-2013-4391İstismar yok | Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servisystemd project · systemd · CWE-190 | Yüksek7,5 | — | %5,4 | 28 Eki 2013 |
32İzleyin | CVE-2018-16865İstismar yok | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | Yüksek7,8 | — | %3,0 | 11 Oca 2019 |
32İzleyin | CVE-2018-15686Kavram kanıtı | systemd: reexec state injection: fgets() on overlong lines leads to line splittingcanonical · ubuntu linux · CWE-502 | Yüksek7,8 | — | %2,3 | 26 Eki 2018 |
31İzleyin | CVE-2016-10156Kavram kanıtı | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowisystemd project · systemd · CWE-264 | Yüksek7,8 | — | %1,2 | 23 Oca 2017 |
31İzleyin | CVE-2017-18078Kavram kanıtı | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinsystemd project · systemd · CWE-59 | Yüksek7,8 | — | %1,1 | 29 Oca 2018 |
31İzleyin | CVE-2023-26604İstismar yok | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in whichdebian · debian linux · CWE-269 | Yüksek7,8 | — | %1,1 | 3 Mar 2023 |
31İzleyin | CVE-2019-3843Kavram kanıtı | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the trsystemd project · systemd · CWE-266 | Yüksek7,8 | — | %0,9 | 26 Nis 2019 |
31İzleyin | CVE-2019-3844Kavram kanıtı | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichsystemd project · systemd · CWE-268 | Yüksek7,8 | — | %0,9 | 26 Nis 2019 |
31İzleyin | CVE-2018-16864İstismar yok | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journasystemd project · systemd · CWE-770 | Yüksek7,8 | — | %0,7 | 11 Oca 2019 |
31İzleyin | CVE-2018-6954İstismar yok | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownesystemd project · systemd · CWE-59 | Yüksek7,8 | — | %0,5 | 13 Şub 2018 |
31İzleyin | CVE-2020-1712İstismar yok | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handsystemd project · systemd · CWE-416 | Yüksek7,8 | — | %0,5 | 31 Mar 2020 |
29İzleyin | CVE-2026-40224İstismar yok | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.systemd project · systemd · CWE-863 | Yüksek7,3 | — | %0,1 | 10 Nis 2026 |
28İzleyin | CVE-2019-3842Kavram kanıtı | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variablesystemd project · systemd · CWE-285 | Yüksek7,0 | — | %1,2 | 9 Nis 2019 |
28İzleyin | CVE-2018-15687Kavram kanıtı | systemd: chown_one() can dereference symlinkscanonical · ubuntu linux · CWE-362 | Yüksek7,0 | — | %1,1 | 26 Eki 2018 |
27İzleyin | CVE-2013-4327İstismar yok | systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictiosystemd project · systemd · CWE-362 | Orta6,9 | — | %0,3 | 3 Eki 2013 |
26İzleyin | CVE-2020-13776İstismar yok | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated bysystemd project · systemd · CWE-269 | Orta6,7 | — | %0,5 | 2 Haz 2020 |
25İzleyin | CVE-2021-33910İstismar yok | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupsystemd project · systemd · CWE-770 | Orta5,5 | — | %8,8 | 20 Tem 2021 |
- CVE-2017-944546Planlayın
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small.
YüksekCVSS 7,5İstismar yokEPSS %55systemd project · systemd28 Haz 2017
- CVE-2015-751040Planlayın
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
KritikCVSS 9,8İstismar yokEPSS %4systemd project · systemd25 Eyl 2017
- CVE-2017-100008240Planlayın
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g.
KritikCVSS 9,8İstismar yokEPSS %4systemd project · systemd7 Tem 2017
- CVE-2018-2102940Planlayın
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
KritikCVSS 9,8İstismar yokEPSS %3systemd project · systemd30 Eki 2019
- CVE-2022-252639İzleyin
A use-after-free vulnerability was found in systemd.
KritikCVSS 9,8İstismar yokEPSS %1systemd project · systemd9 Eyl 2022
- CVE-2017-1590837İzleyin
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in th
YüksekCVSS 7,5İstismar yokEPSS %24systemd project · systemd26 Eki 2017
- CVE-2017-921735İzleyin
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty qu
YüksekCVSS 7,5İstismar yokEPSS %15systemd project · systemd24 May 2017
- CVE-2018-1568835İzleyin
Out-of-Bounds write in systemd-networkd dhcpv6 option handling
YüksekCVSS 8,8İstismar yokEPSS %2systemd project · systemd26 Eki 2018
- CVE-2013-439132İzleyin
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of servi
YüksekCVSS 7,5İstismar yokEPSS %5systemd project · systemd28 Eki 2013
- CVE-2018-1686532İzleyin
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
YüksekCVSS 7,8İstismar yokEPSS %3systemd project · systemd11 Oca 2019
- CVE-2018-1568632İzleyin
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
YüksekCVSS 7,8Kavram kanıtıEPSS %2canonical · ubuntu linux26 Eki 2018
- CVE-2016-1015631İzleyin
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowi
YüksekCVSS 7,8Kavram kanıtıEPSS %1systemd project · systemd23 Oca 2017
- CVE-2017-1807831İzleyin
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlin
YüksekCVSS 7,8Kavram kanıtıEPSS %1systemd project · systemd29 Oca 2018
- CVE-2023-2660431İzleyin
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which
YüksekCVSS 7,8İstismar yokEPSS %1debian · debian linux3 Mar 2023
- CVE-2019-384331İzleyin
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the tr
YüksekCVSS 7,8Kavram kanıtıEPSS %1systemd project · systemd26 Nis 2019
- CVE-2019-384431İzleyin
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which
YüksekCVSS 7,8Kavram kanıtıEPSS %1systemd project · systemd26 Nis 2019
- CVE-2018-1686431İzleyin
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journa
YüksekCVSS 7,8İstismar yokEPSS %1systemd project · systemd11 Oca 2019
- CVE-2018-695431İzleyin
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain owne
YüksekCVSS 7,8İstismar yokEPSS %1systemd project · systemd13 Şub 2018
- CVE-2020-171231İzleyin
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while hand
YüksekCVSS 7,8İstismar yokEPSS %0systemd project · systemd31 Mar 2020
- CVE-2026-4022429İzleyin
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
YüksekCVSS 7,3İstismar yokEPSS %0systemd project · systemd10 Nis 2026
- CVE-2019-384228İzleyin
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable
YüksekCVSS 7,0Kavram kanıtıEPSS %1systemd project · systemd9 Nis 2019
- CVE-2018-1568728İzleyin
systemd: chown_one() can dereference symlinks
YüksekCVSS 7,0Kavram kanıtıEPSS %1canonical · ubuntu linux26 Eki 2018
- CVE-2013-432727İzleyin
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictio
OrtaCVSS 6,9İstismar yokEPSS %0systemd project · systemd3 Eki 2013
- CVE-2020-1377626İzleyin
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by
OrtaCVSS 6,7İstismar yokEPSS %0systemd project · systemd2 Haz 2020
- CVE-2021-3391025İzleyin
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdup
OrtaCVSS 5,5İstismar yokEPSS %9systemd project · systemd20 Tem 2021