Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ktsuss Project Subscribe
Filtered by product Ktsuss
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-2921 1 Ktsuss Project 1 Ktsuss 2019-11-21 10.0 HIGH 9.8 CRITICAL
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CVE-2011-2922 1 Ktsuss Project 1 Ktsuss 2019-11-21 7.2 HIGH 7.8 HIGH
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.