Dbus

Vendor:

First CVE: Feb 29, 2008 · Active for 18 years

24
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
4.0
Avg CVSS
Higher Avg CVSS than 2% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Dbus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 29, 2008
18 years ago
Most Recent CVE
Jun 8, 2023
1,142 days ago

CVE Severity & Scoring

Dbus24 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local4 (16.7%)
Network4 (16.7%)
Unknown16 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (33.3%)
High0 (0.0%)
Unknown16 (66.7%)
User Interaction
None8 (33.3%)
Unknown16 (66.7%)
Required0 (0.0%)
Privileges Required
Low7 (29.2%)
High0 (0.0%)
None1 (4.2%)
Unknown16 (66.7%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that
Oct 10, 20226.524NONO
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), a
Jun 11, 20197.124NONO
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multip
Feb 15, 20217.823NONO
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a
Oct 7, 20082.121NOYES
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring in
Jun 8, 20236.520NONO
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that
Oct 10, 20226.518NONO
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that
Oct 10, 20226.517NONO
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descr
Jun 8, 20205.517NONO
The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-nati
Jun 22, 20114.617NONO
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, w
Feb 29, 20084.617NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Dbus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.811.90.3%00
1.9.611.90.3%00
1.9.411.90.3%00
1.9.211.90.3%00
1.9.022.00.4%00
1.8.822.00.4%00
1.8.672.40.4%00
1.8.482.30.4%00
1.8.292.50.4%00
1.8.1411.90.3%00
1.8.1211.90.3%00
1.8.1011.90.3%00
1.8.092.50.4%00
1.7.211.90.4%00
1.7.011.90.4%00
1.6.882.60.4%00
1.6.682.60.4%00
1.6.482.60.4%00
1.6.2811.90.3%00
1.6.2611.90.3%00