Vulnerabilities (CVE)

Filtered by vendor Presire Subscribe
Filtered by product Qsnapper
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-41046 1 Presire 1 Qsnapper 2026-06-28 N/A 7.3 HIGH
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
CVE-2026-41045 1 Presire 1 Qsnapper 2026-06-28 N/A 8.1 HIGH
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
CVE-2026-41047 1 Presire 1 Qsnapper 2026-06-28 N/A 5.5 MEDIUM
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
CVE-2026-41048 1 Presire 1 Qsnapper 2026-06-28 N/A 7.1 HIGH
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
CVE-2026-41049 1 Presire 1 Qsnapper 2026-06-27 N/A 7.1 HIGH
Incorrect caching of authentication between different users of theĀ  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.