RSS   Vulnerabilities for 'WICD'   RSS

2014-04-07
 
CVE-2012-2095

CWE-20
 

 
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.

 
2012-06-29
 
CVE-2012-0813

CWE-255
 

 
Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.

 
2009-02-09
 
CVE-2009-0489

 

 
The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.

 


Copyright 2024, cxsecurity.com

 

Back to Top