Vulnerabilities
Vulnerable Software
Presire:  >> Qsnapper  >> 1.0.3  Security Vulnerabilities
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
CVSS Score
7.3
EPSS Score
0.002
Published
2026-06-22
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-06-22
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
CVSS Score
8.4
EPSS Score
0.001
Published
2026-06-22
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
CVSS Score
8.1
EPSS Score
0.001
Published
2026-06-22


Contact Us

Shodan ® - All rights reserved