Packagekit Project / Packagekit
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-10294 | PackageKit API pk-transaction.c g_file_test improper authorization | MEDIUM | 5.3 | Jun 1, 2026 |
| CVE-2026-41651 | PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root | HIGH | 8.8 | Apr 22, 2026 |
| CVE-2024-0217 | Packagekitd: use-after-free in idle function callback | LOW | 3.3 | Jan 3, 2024 |
| CVE-2022-0987 | PackageKit: Information Disclosure in Transaction Interface via timing | LOW | 3.3 | Jun 28, 2022 |
| CVE-2020-16122 | Packagekit's apt backend lets user install untrusted local packages | HIGH | 8.2 | Nov 7, 2020 |
| CVE-2020-16121 | PackageKit error messages leak presence and mimetype of files to unprivileged users | LOW | 3.3 | Nov 7, 2020 |
| CVE-2011-2515 | PackageKit: installs unsigned RPM packages as though they were signed | MEDIUM | 5.3 | Nov 27, 2019 |
| CVE-2018-1106 | PackageKit: authentication bypass allows to install signed packages without administrator privileges | MEDIUM | 5.5 | Apr 23, 2018 |
| CVE-2013-1764 | PackageKit: downgrade packages when using the Zypper backend | LOW | 2.1 | Apr 16, 2014 |
Showing 1 to 8 of 8 CVEs