Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2015-3255
Disclosure Date: October 26, 2015 (last updated October 05, 2023)
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
0
Attacker Value
Unknown
CVE-2015-3256
Disclosure Date: October 26, 2015 (last updated October 05, 2023)
PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "javascript rule evaluation."
0
Attacker Value
Unknown
CVE-2015-3218
Disclosure Date: October 26, 2015 (last updated October 05, 2023)
The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.
0
Attacker Value
Unknown
CVE-2015-4625
Disclosure Date: October 26, 2015 (last updated October 05, 2023)
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
0
Attacker Value
Unknown
CVE-2013-4288
Disclosure Date: October 03, 2013 (last updated October 05, 2023)
Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.
0