Index
Bugtraq
Pełna lista
Błędy
Sztuczki
Exploity
Dorks list
Tylko z CVE
Tylko z CWE
Bogus
Ranking
CVEMAP
Świeża lista CVE
Producenci
Produkty
Słownik CWE
Sprawdź nr. CVE
Sprawdź nr. CWE
Szukaj
W Bugtraq
W bazie CVE
Po autorze
Po nr. CVE
Po nr. CWE
Po producencie
Po produkcie
RSS
Bugtraq
CVEMAP
CVE Produkty
Tylko Błędy
Tylko Exploity
Tylko Dorks
Więcej
cIFrex
Facebook
Twitter
Donate
O bazie
Lang
Polish
English
Submit
Podatności dla
'GVFS'
2019-06-11
CVE-2019-12795
CWE-285
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)
2019-05-29
CVE-2019-12449
CWE-269
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
CVE-2019-12448
CWE-362
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.
CVE-2019-12447
CWE-269
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
2019-03-25
CVE-2019-3827
CWE-275
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
>>>
Vendor:
Gnome
89
Produkty
Gnumeric
GDM
Gnome libs
Gnome-lokkit
Esound
Gnorpm
Libgtop daemon
Nautilus
Evolution
Bonobo
Gnome-terminal
Gtkhtml
EOG
Balsa
Batalla naval
Gdkpixbuf
GPDF
Libvte4
Libzvt2
Epiphany
Gedit
Networkmanager
Libgda2
DIA
Dwarf http server
Screensaver
Dhcdbd
Libgsf
Libsoup
Gconf
Power manager
Ekiga
Gnome-vfs
Gnome
YELP
GLIB
ORCA
Vinagre
Rhythmbox
Nautilus-python
Evolution-data-server
Gupnp
Gmime
Evince
Gnome-shell
Tomboy
Ifcfg-rh plug-in
Empathy
Update-manager-core
Gdk-pixbuf
Libgdata
At-spi2-atk
Librsvg
Libsocialweb
Gnome-keyring
Gnome display manager
Gnome online accounts
Geary
GCAB
VALA
Byzanz
Eye of gnome
Shotwell
Gtk-vnc
Libcroco
Gnome-session
Libgxps
Librest
Gthumb
Seahorse
GVFS
Gnome-desktop
Evolution-ews
Network manager vpnc
Gnome-system-log
Gnome-font-viewer
Gnome keyring
Evolution data server
File-roller
Glib-networking
Gnome-autoar
Libgrss
Libgda
Libgfbgraph
Grilo
Evolution-rss
Libzapojit
Ocrfeeder
Caribou
Copyright
2024
, cxsecurity.com
Back to Top