The D-Bus Project maintains a core inter-process communication system that, despite serving a single narrowly scoped product, is fundamental to desktop and embedded Linux environments where it mediates service discovery and message passing across the system. Its vulnerability surface reflects the parsing and access-control complexity of a privileged daemon that handles untrusted input from multiple local processes. Defenders should monitor this project's advisories closely for desktop and IoT deployments that depend on D-Bus; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by D Bus Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2200MEDIUM The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nati | Jun 22, 2011 | 4.6 | 17 | NO | NO |
CVE-2014-3635MEDIUM Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allo | Sep 22, 2014 | 4.4 | 16 | NO | NO |
CVE-2014-3477MEDIUM The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibi | Jul 1, 2014 | 4.0 | 15 | NO | NO |
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants. | Dec 30, 2010 | 2.1 | 13 | NO | NO |
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing th | Oct 25, 2014 | 1.9 | 11 | NO | NO |
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection | Sep 22, 2014 | 2.1 | 11 | NO | NO |
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a la | Sep 22, 2014 | 2.1 | 11 | NO | NO |
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another use | Jun 29, 2005 | 2.1 | 11 | NO | NO |
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a | Dec 14, 2006 | 1.7 | 10 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by D Bus Project.
Media articles that mention a CVE ID that affects a product developed by D Bus Project — matched by CVE ID, not by vendor name.