CVE Tools

Polkit-project

5 CVEs tracked since 2013. Since Oct 2013, none of them reached CISA KEV.

Polkit-project CVEs per month

Oct 2013 to Oct 2015. Point at a month, or focus the strip and use the arrow keys.
Polkit-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-1010
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-1040

Products

The products that kept showing up in Polkit-project's monthly top three, with their CVEs summed over those months.

  1. Polkit52 months

Latest CVEs

The 11 most recently published vulnerabilities affecting Polkit-project.

  1. CVE-2021-4115There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NO...5.5
  2. CVE-2021-3560It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivil...7.8
  3. CVE-2021-4034A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users acc...7.8
  4. CVE-2019-6133In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to ...6.7
  5. CVE-2018-19788A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.8.8
  6. CVE-2018-1116A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger...4.4
  7. CVE-2015-4625Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which trigge...4.6
  8. CVE-2015-3256PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "ja...4.6
  9. CVE-2015-3255The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in...4.6
  10. CVE-2015-3218The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer deref...2.1
  11. CVE-2013-4288Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is pe...7.2

The record

Peak rank
#39 in Oct 2015
Busiest month shown
Oct 2015, 4 CVEs
Months with a KEV entry
0 since Oct 2013
Monthly snapshots
2 since 2013
Polkit-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store