Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2012-6648
Disclosure Date: May 22, 2014 (last updated October 05, 2023)
gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-0943 is used for the guest-account issue.
0
Attacker Value
Unknown
CVE-2011-1709
Disclosure Date: June 14, 2011 (last updated October 04, 2023)
GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.
0
Attacker Value
Unknown
CVE-2011-0727
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
0
Attacker Value
Unknown
CVE-2009-2697
Disclosure Date: September 04, 2009 (last updated October 04, 2023)
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
0
Attacker Value
Unknown
CVE-2007-3381
Disclosure Date: August 07, 2007 (last updated October 04, 2023)
The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
0
Attacker Value
Unknown
CVE-2006-6105
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.
0
Attacker Value
Unknown
CVE-2006-2452
Disclosure Date: June 09, 2006 (last updated October 04, 2023)
GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.
0
Attacker Value
Unknown
CVE-2006-1057
Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
0
Attacker Value
Unknown
CVE-2003-0794
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.
0
Attacker Value
Unknown
CVE-2003-0793
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).
0