Search CVE reports


Toggle filters

41 – 46 of 46 results


CVE-2009-1189

Medium priority
Fixed

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. ...

1 affected package

dbus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
Show less packages

CVE-2008-4311

Medium priority
Ignored

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related...

1 affected package

dbus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
Show less packages

CVE-2008-3834

Low priority
Fixed

The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed...

1 affected package

dbus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
Show less packages

CVE-2008-0595

Medium priority

Some fixes available 4 of 5

dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access...

1 affected package

dbus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
Show less packages

CVE-2006-6107

Medium priority
Fixed

Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).

1 affected package

dbus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
Show less packages

CVE-2005-0201

Medium priority
Fixed

D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.

5 affected packages

dbus, dbus-glib, dbus-python, dbus-qt3, dbus-sharp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dbus — — — — —
dbus-glib — — — — —
dbus-python — — — — —
dbus-qt3 — — — — —
dbus-sharp — — — — —
Show less packages