Vulnerabilities (CVE)

Filtered by vendor Sddm Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14345 1 Sddm Project 1 Sddm 2019-10-03 6.0 MEDIUM 7.5 HIGH
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.
CVE-2014-7271 2 Fedoraproject, Sddm Project 2 Fedora, Sddm 2018-03-27 4.6 MEDIUM 7.8 HIGH
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
CVE-2014-7272 2 Fedoraproject, Sddm Project 2 Fedora, Sddm 2018-03-27 7.2 HIGH 7.8 HIGH
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).