Polkit Project / Polkit
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-4115 | polkit: file descriptor leak allows an unprivileged user to cause a crash | MEDIUM | 6.2 | Feb 21, 2022 |
| CVE-2021-3560 KEV | polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync() | HIGH | 7.8 | Feb 16, 2022 |
| CVE-2021-4034 KEV | polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector | HIGH | 7.8 | Jan 28, 2022 |
| CVE-2019-6133 | polkit: Temporary auth hijacking via PID reuse and non-atomic fork | HIGH | 7.3 | Jan 11, 2019 |
| CVE-2018-19788 | polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass | HIGH | 8.8 | Dec 3, 2018 |
| CVE-2018-1116 | polkit: Improper authorization in polkit_backend_interactive_authority_check_authorization function in polkitd | MEDIUM | 4.4 | Jul 10, 2018 |
| CVE-2015-4625 | polkit: potential information disclosure vulnerability due to cookie counter wrapping | MEDIUM | 4.6 | Oct 26, 2015 |
| CVE-2015-3256 | polkit: Memory corruption via javascript rule evaluation | MEDIUM | 4.6 | Oct 26, 2015 |
| CVE-2015-3255 | polkit: Heap-corruption on duplicate ids | MEDIUM | 4.6 | Oct 26, 2015 |
| CVE-2015-3218 | polkit: crash authentication_agent_new with invalid object path in RegisterAuthenticationAgent | LOW | 2.1 | Oct 26, 2015 |
| CVE-2013-4288 | polkit: unix-process subject for authorization is racy | HIGH | 7.2 | Oct 3, 2013 |
Showing 1 to 11 of 11 CVEs