libuser project records
3 published records for vendor libuser project.
Researcher profile
- Entered KEV
- 1 · 33.3%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- 4033 days
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2015-3246Weaponized | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, wredhat · enterprise linux · CWE-264 | Medium5.1 | KEV | 8.8% | Aug 11, 2015 |
25Monitor | CVE-2012-5630No exploit | libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.libuser project · libuser · CWE-367 | Medium6.3 | — | 0.3% | Nov 25, 2019 |
22Monitor | CVE-2012-5644No exploit | libuser has information disclosure when moving user's home directorylibuser project · libuser · CWE-200 | Medium5.5 | — | 0.4% | Nov 25, 2019 |
- CVE-2015-324653Plan
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, w
MediumCVSS 5.1KEVWeaponizedEPSS 9%redhat · enterprise linuxAug 11, 2015
- CVE-2012-563025Monitor
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
MediumCVSS 6.3No exploitEPSS 0%libuser project · libuserNov 25, 2019
- CVE-2012-564422Monitor
libuser has information disclosure when moving user's home directory
MediumCVSS 5.5No exploitEPSS 0%libuser project · libuserNov 25, 2019