Vulnerabilities > Sddm Project

DATE CVE VULNERABILITY TITLE RISK
2020-11-04 CVE-2020-28049 Race Condition vulnerability in multiple products
An issue was discovered in SDDM before 0.19.0.
6.3
2018-07-17 CVE-2018-14345 Insufficient Session Expiration vulnerability in Sddm Project Sddm
An issue was discovered in SDDM through 0.17.0.
network
high complexity
sddm-project CWE-613
7.5
2018-03-08 CVE-2014-7272 Permissions, Privileges, and Access Controls vulnerability in multiple products
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
local
low complexity
sddm-project fedoraproject CWE-264
7.8
2018-03-08 CVE-2014-7271 Missing Authentication for Critical Function vulnerability in multiple products
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
local
low complexity
sddm-project fedoraproject CWE-306
7.8