← Back

Presire

presire

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Qsnapper
qsnapper

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Presire
1Qsnapper
Jul 8, 2026
Jun 22, 2026
8.4 HIGH· v4
7.1 HIGH· v3
N/A· v2
Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
1Presire
1Qsnapper
Jul 7, 2026
Jun 22, 2026
8.4 HIGH· v4
7.1 HIGH· v3
N/A· v2
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
1Presire
1Qsnapper
Jul 7, 2026
Jun 22, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
1Presire
1Qsnapper
Jun 28, 2026
Jun 22, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate pri...Show more
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.Show less
1Presire
1Qsnapper
Jun 28, 2026
Jun 22, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.