CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
49740 | CVE-2011-1828 | Candidate | usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command. | Assigned (20110427) | None (candidate not yet proposed) | View | |
61010 | CVE-2013-1063 | Candidate | usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. | Assigned (20130111) | None (candidate not yet proposed) | View | |
103731 | CVE-2017-6911 | Candidate | USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack. | Assigned (20170315) | None (candidate not yet proposed) | View | |
103715 | CVE-2017-6895 | Candidate | USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml. | Assigned (20170314) | None (candidate not yet proposed) | View | |
68582 | CVE-2014-1287 | Candidate | USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages. | Assigned (20140108) | None (candidate not yet proposed) | View |
Page 807 of 20943, showing 5 records out of 104715 total, starting on record 4031, ending on 4035