Vulnerabilities > Systemd Project > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-29 CVE-2017-18078 Link Following vulnerability in multiple products
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
local
low complexity
systemd-project debian opensuse CWE-59
7.8
2017-09-25 CVE-2015-7510 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Systemd Project Systemd 223
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
network
low complexity
systemd-project CWE-119
7.5
2017-01-23 CVE-2016-10156 Permissions, Privileges, and Access Controls vulnerability in Systemd Project Systemd 228
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root.
local
low complexity
systemd-project CWE-264
7.2
2013-10-28 CVE-2013-4391 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.
network
low complexity
systemd-project debian CWE-190
7.5