0
I Use This!
Activity Not Available
Analyzed 8 months ago. based on code collected 8 months ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2021-4034 BDSA-2022-0246 High Jan 28, 2022 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged more...
0.9.2, 0.9.1, 0.120, 0.119, 0.112.1, 0.118, 0.117, 0.116, 0.115, 0.114
CVE-2021-3560 BDSA-2021-1677 High Feb 16, 2022 It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the roo more...
0.9.2, 0.9.1, 0.112.1, 0.118, 0.117, 0.116, 0.115, 0.114, 0.113, 0.112
CVE-2018-1116 BDSA-2018-2272 Medium Jul 10, 2018 A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd more...
0.9.2, 0.9.1, 0.112.1, 0.114, 0.113, 0.112, 0.111, 0.110, 0.109, 0.108
CVE-2015-4625 Oct 26, 2015 Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creati more...
0.9.2, 0.9.1, 0.112, 0.111, 0.110, 0.109, 0.108, 0.107, 0.106, 0.105
CVE-2015-3256 Oct 26, 2015 PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain priv more...
0.9.2, 0.9.1, 0.112, 0.111, 0.110, 0.109, 0.108, 0.107, 0.106, 0.105
CVE-2015-3255 Oct 26, 2015 The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users more...
0.9.2, 0.9.1, 0.112, 0.111, 0.110, 0.109, 0.108, 0.107, 0.106, 0.105
CVE-2015-3218 Oct 26, 2015 The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to more...
0.9.2, 0.9.1, 0.112, 0.111, 0.110, 0.109, 0.108, 0.107, 0.106, 0.105
CVE-2013-4288 Oct 03, 2013 Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexe more...
0.9.2, 0.9.1, 0.112, 0.111, 0.110, 0.109, 0.108, 0.107, 0.106, 0.105
BDSA-2025-6906 Medium Jul 15, 2025 Polkit is vulnerable to an out-of-bounds write due to improper handling of XML policies with deeply nested elements. This could allow an attacker with more...
BDSA-2022-0510 Medium Feb 21, 2022 Polkit is vulnerable to denial-of-service (DoS) due to the improper handling of error conditions, which can lead to the exhaustion of file descriptors. more...