Freedesktop / Dbus
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-34969 | dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered | MEDIUM | 6.5 | Jun 8, 2023 |
| CVE-2022-42012 | dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly | MEDIUM | 6.5 | Oct 9, 2022 |
| CVE-2022-42011 | dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type | MEDIUM | 6.5 | Oct 9, 2022 |
| CVE-2022-42010 | dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets | MEDIUM | 6.5 | Oct 9, 2022 |
| CVE-2020-35512 | dbus: users with the same numeric UID could lead to use-after-free and undefined behaviour | HIGH | 7.8 | Feb 15, 2021 |
| CVE-2020-12049 | dbus: denial of service via file descriptor leak | MEDIUM | 6.5 | Jun 8, 2020 |
| CVE-2019-12749 | dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass | HIGH | 7.1 | Jun 11, 2019 |
| CVE-2015-0245 | dbus: denial of service in dbus systemd activation | LOW | 1.9 | Feb 13, 2015 |
| CVE-2014-7824 | dbus: local denial of service via incomplete fix for CVE-2014-3636 | LOW | 2.1 | Nov 18, 2014 |
| CVE-2014-3636 | dbus: denial of service by queuing or splitting file descriptors | LOW | 1.9 | Oct 25, 2014 |
| CVE-2014-3639 | dbus: denial of service flaw in incomplete connection handling | LOW | 2.1 | Sep 22, 2014 |
| CVE-2014-3638 | dbus: denial of service in method call handling | LOW | 2.1 | Sep 22, 2014 |
| CVE-2014-3637 | dbus: denial of service by creating unkillable D-Bus connections | LOW | 2.1 | Sep 22, 2014 |
| CVE-2014-3635 | dbus: heap-based buffer overflow flaw in file descriptor passing | MEDIUM | 4.4 | Sep 22, 2014 |
| CVE-2014-3533 | dbus: denial of service when forwarding invalid file descriptors | LOW | 2.1 | Jul 19, 2014 |
| CVE-2014-3532 | dbus: denial of service in file descriptor passing feature | LOW | 2.1 | Jul 19, 2014 |
| CVE-2014-3477 | dbus: denial of service flaw in dbus-daemon | MEDIUM | 4.0 | Jul 1, 2014 |
| CVE-2013-2168 | dbus: Crash of system services that use libdbus (DoS) due to non-portable use of va_list in UNIX format string wrapper | LOW | 1.9 | Jul 3, 2013 |
| CVE-2011-2533 | dbus: Possibility of symlink attack in /tmp during compilation | LOW | 3.3 | Jun 22, 2011 |
| CVE-2011-2200 | dbus: Local DoS via messages with non-native byte order | MEDIUM | 4.6 | Jun 22, 2011 |
| CVE-2009-1189 | dbus: invalid fix for CVE-2008-3834 | LOW | 3.6 | Apr 27, 2009 |
| CVE-2008-4311 | dbus: incorrect use of [send|receive]_requested_reply policy rule attribute in system.conf | MEDIUM | 4.6 | Dec 10, 2008 |
| CVE-2008-3834 | dbus denial of service | LOW | 2.1 | Oct 7, 2008 |
| CVE-2008-0595 | dbus security policy circumvention | MEDIUM | 4.6 | Feb 29, 2008 |
Showing 1 to 24 of 24 CVEs