D Bus

Vendor:

First CVE: Jun 29, 2005 · Active for 21 years

9
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
2.8
Avg CVSS
Higher Avg CVSS than 1% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact D Bus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2005
21 years ago
Most Recent CVE
Oct 25, 2014
4,294 days ago

CVE Severity & Scoring

D Bus9 CVEs
All CVEs353,173 CVEs
LowMedium
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (11.1%)
Unknown8 (88.9%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nati
Jun 22, 20114.617NONO
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allo
Sep 22, 20144.416NONO
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibi
Jul 1, 20144.015NONO
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.
Dec 30, 20102.113NONO
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing th
Oct 25, 20141.911NONO
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection
Sep 22, 20142.111NONO
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a la
Sep 22, 20142.111NONO
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another use
Jun 29, 20052.111NONO
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a
Dec 14, 20061.710NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For D Bus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.2.4.624.30.4%00
1.2.4.424.30.4%00
1.2.4.224.30.4%00
1.0.111.70.4%00
1.011.70.4%00
0.2311.70.4%00
0.2211.70.4%00
0.2111.70.4%00
0.2011.70.4%00
0.1311.70.4%00