D Bus
Vendor:
First CVE: Jun 29, 2005 · Active for 21 years
9
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
2.8
Avg CVSS
Higher Avg CVSS than 1% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact D Bus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2005
21 years ago
Most Recent CVE
Oct 25, 2014
4,294 days ago
CVE Severity & Scoring
D Bus9 CVEs
67%
33%
All CVEs353,173 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (11.1%)
Unknown8 (88.9%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2200MEDIUM The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nati | Jun 22, 2011 | 4.6 | 17 | NO | NO |
CVE-2014-3635MEDIUM Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allo | Sep 22, 2014 | 4.4 | 16 | NO | NO |
CVE-2014-3477MEDIUM The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibi | Jul 1, 2014 | 4.0 | 15 | NO | NO |
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants. | Dec 30, 2010 | 2.1 | 13 | NO | NO |
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing th | Oct 25, 2014 | 1.9 | 11 | NO | NO |
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection | Sep 22, 2014 | 2.1 | 11 | NO | NO |
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a la | Sep 22, 2014 | 2.1 | 11 | NO | NO |
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another use | Jun 29, 2005 | 2.1 | 11 | NO | NO |
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a | Dec 14, 2006 | 1.7 | 10 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For D Bus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.2.4.6 | 2 | 4.3 | 0.4% | 0 | 0 |
| 1.2.4.4 | 2 | 4.3 | 0.4% | 0 | 0 |
| 1.2.4.2 | 2 | 4.3 | 0.4% | 0 | 0 |
| 1.0.1 | 1 | 1.7 | 0.4% | 0 | 0 |
| 1.0 | 1 | 1.7 | 0.4% | 0 | 0 |
| 0.23 | 1 | 1.7 | 0.4% | 0 | 0 |
| 0.22 | 1 | 1.7 | 0.4% | 0 | 0 |
| 0.21 | 1 | 1.7 | 0.4% | 0 | 0 |
| 0.20 | 1 | 1.7 | 0.4% | 0 | 0 |
| 0.13 | 1 | 1.7 | 0.4% | 0 | 0 |