D-Bus is a system message bus widely used in Linux and Unix environments to enable inter-process communication across desktop and server deployments, presenting a focused but deeply embedded attack surface. The vendor's disclosed vulnerabilities center on the core D-Bus daemon itself and reflect the complexity inherent in managing privileged message routing and access control in a multi-user system. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by D Bus over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2200MEDIUM The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nati | Jun 22, 2011 | 4.6 | 17 | NO | NO |
CVE-2014-3635MEDIUM Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allo | Sep 22, 2014 | 4.4 | 16 | NO | NO |
CVE-2014-3477MEDIUM The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibi | Jul 1, 2014 | 4.0 | 15 | NO | NO |
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants. | Dec 30, 2010 | 2.1 | 13 | NO | NO |
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing th | Oct 25, 2014 | 1.9 | 11 | NO | NO |
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection | Sep 22, 2014 | 2.1 | 11 | NO | NO |
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a la | Sep 22, 2014 | 2.1 | 11 | NO | NO |
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another use | Jun 29, 2005 | 2.1 | 11 | NO | NO |
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a | Dec 14, 2006 | 1.7 | 10 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by D Bus.
Media articles that mention a CVE ID that affects a product developed by D Bus — matched by CVE ID, not by vendor name.