Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2020-28049

Disclosure Date: November 04, 2020 (last updated November 08, 2023)
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Attacker Value
Unknown

CVE-2018-14345

Disclosure Date: July 17, 2018 (last updated November 27, 2024)
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.
0
Attacker Value
Unknown

CVE-2014-7272

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
0
Attacker Value
Unknown

CVE-2014-7271

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
0
Attacker Value
Unknown

CVE-2015-0856

Disclosure Date: November 24, 2015 (last updated October 05, 2023)
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
0