Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-41045 | 1 Presire | 1 Qsnapper | 2026-06-23 | 8.1 High |
| A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user. | ||||
| CVE-2026-41046 | 1 Presire | 1 Qsnapper | 2026-06-23 | 7.3 High |
| A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root. | ||||
| CVE-2026-41047 | 1 Presire | 1 Qsnapper | 2026-06-23 | N/A |
| Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information. | ||||
| CVE-2026-41048 | 1 Presire | 1 Qsnapper | 2026-06-23 | N/A |
| Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot". | ||||
| CVE-2026-41049 | 1 Presire | 1 Qsnapper | 2026-06-23 | N/A |
| Incorrect caching of authentication between different users of theĀ qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them. | ||||
Page 1 of 1.