Перейти к содержимому
Noroxi

Записи Linux-PAM

18 опубликованных записей вендора linux-pam.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
94,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2020-27780
    40В плане

    A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    linux-pam · linux-pam17 дек. 2020 г.

  • CVE-2022-28321
    39Наблюдать

    The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    linux-pam · linux-pam19 сент. 2022 г.

  • CVE-2010-4708
    28Наблюдать

    The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lo

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2015-3238
    27Наблюдать

    The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, a

    СредняяCVSS 6,5Эксплойта нетEPSS 3 %

    linux-pam · linux-pam24 авг. 2015 г.

  • CVE-2009-0887
    27Наблюдать

    Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fil

    СредняяCVSS 6,6Эксплойта нетEPSS 2 %

    linux-pam · linux-pam12 мар. 2009 г.

  • CVE-2010-3853
    27Наблюдать

    pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2014-2583
    24Наблюдать

    Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users

    СредняяCVSS 5,8Эксплойта нетEPSS 4 %

    linux-pam · linux-pam10 апр. 2014 г.

  • CVE-2024-22365
    22Наблюдать

    linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat c

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    linux-pam · linux-pam6 февр. 2024 г.

  • CVE-2010-4706
    19Наблюдать

    The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2010-4707
    19Наблюдать

    The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL fi

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2011-3148
    18Наблюдать

    Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local use

    СредняяCVSS 4,6Эксплойта нетEPSS 1 %

    linux-pam · linux-pam22 июл. 2012 г.

  • CVE-2010-3435
    18Наблюдать

    The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2009-0579
    18Наблюдать

    Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass i

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    linux-pam · linux-pam16 апр. 2009 г.

  • CVE-2010-3430
    18Наблюдать

    The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2024-10041
    18Наблюдать

    Pam: libpam: libpam vulnerable to read hashed password

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    linux-pam · linux-pam23 окт. 2024 г.

  • CVE-2010-3316
    13Наблюдать

    The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of th

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.

  • CVE-2011-3149
    8Наблюдать

    The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when

    НизкаяCVSS 2,1Эксплойта нетEPSS 1 %

    linux-pam · linux-pam22 июл. 2012 г.

  • CVE-2010-3431
    7Наблюдать

    The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return val

    НизкаяCVSS 1,9Эксплойта нетEPSS 0 %

    linux-pam · linux-pam24 янв. 2011 г.