Spice-GTK Project Spice-GTK 0.14

CPE Details

Spice-GTK Project Spice-GTK 0.14
0.14
2019-06-17 11:48 +00:00
2019-06-17 11:48 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:spice-gtk_project:spice-gtk:0.14:*:*:*:*:*:*:*

Informations

Vendor

spice-gtk_project

Product

spice-gtk

Version

0.14

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-12194 2018-03-14 21:00 +00:00 A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
9.8
CRITICAL
CVE-2016-3066 2017-06-06 16:00 +00:00 The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
6.5
MEDIUM
CVE-2013-4324 2013-10-03 19:00 +00:00 spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
4.6
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.