Linux-PAM records
18 published records for vendor linux-pam.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 94.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-27780No exploit | A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.linux-pam · linux-pam · CWE-287 | Critical9.8 | — | 2.0% | Dec 17, 2020 |
39Monitor | CVE-2022-28321No exploit | The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.linux-pam · linux-pam · CWE-287 | Critical9.8 | — | 1.5% | Sep 19, 2022 |
28Monitor | CVE-2010-4708No exploit | The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lolinux-pam · linux-pam | High7.2 | — | 0.4% | Jan 24, 2011 |
27Monitor | CVE-2015-3238No exploit | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, alinux-pam · linux-pam · CWE-200 | Medium6.5 | — | 2.7% | Aug 24, 2015 |
27Monitor | CVE-2009-0887No exploit | Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fillinux-pam · linux-pam · CWE-189 | Medium6.6 | — | 1.9% | Mar 12, 2009 |
27Monitor | CVE-2010-3853No exploit | pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service linux-pam · linux-pam | Medium6.9 | — | 0.4% | Jan 24, 2011 |
24Monitor | CVE-2014-2583No exploit | Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users linux-pam · linux-pam · CWE-22 | Medium5.8 | — | 4.1% | Apr 10, 2014 |
22Monitor | CVE-2024-22365No exploit | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat clinux-pam · linux-pam · CWE-664 | Medium5.5 | — | 0.5% | Feb 6, 2024 |
19Monitor | CVE-2010-4706No exploit | The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle alinux-pam · linux-pam | Medium4.9 | — | 0.4% | Jan 24, 2011 |
19Monitor | CVE-2010-4707No exploit | The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL filinux-pam · linux-pam · CWE-399 | Medium4.9 | — | 0.4% | Jan 24, 2011 |
18Monitor | CVE-2011-3148No exploit | Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local uselinux-pam · linux-pam · CWE-119 | Medium4.6 | — | 0.7% | Jul 22, 2012 |
18Monitor | CVE-2010-3435No exploit | The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directorieslinux-pam · linux-pam | Medium4.7 | — | 0.4% | Jan 24, 2011 |
18Monitor | CVE-2009-0579No exploit | Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass ilinux-pam · linux-pam · CWE-264 | Medium4.6 | — | 0.3% | Apr 16, 2009 |
18Monitor | CVE-2010-3430No exploit | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the requiredlinux-pam · linux-pam | Medium4.7 | — | 0.3% | Jan 24, 2011 |
18Monitor | CVE-2024-10041No exploit | Pam: libpam: libpam vulnerable to read hashed passwordlinux-pam · linux-pam · CWE-922 | Medium4.7 | — | 0.3% | Oct 23, 2024 |
13Monitor | CVE-2010-3316No exploit | The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of thlinux-pam · linux-pam | Low3.3 | — | 0.4% | Jan 24, 2011 |
8Monitor | CVE-2011-3149No exploit | The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle whenlinux-pam · linux-pam · CWE-119 | Low2.1 | — | 0.5% | Jul 22, 2012 |
7Monitor | CVE-2010-3431No exploit | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return vallinux-pam · linux-pam | Low1.9 | — | 0.3% | Jan 24, 2011 |
- CVE-2020-2778040Plan
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.
CriticalCVSS 9.8No exploitEPSS 2%linux-pam · linux-pamDec 17, 2020
- CVE-2022-2832139Monitor
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.
CriticalCVSS 9.8No exploitEPSS 1%linux-pam · linux-pamSep 19, 2022
- CVE-2010-470828Monitor
The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lo
HighCVSS 7.2No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2015-323827Monitor
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, a
MediumCVSS 6.5No exploitEPSS 3%linux-pam · linux-pamAug 24, 2015
- CVE-2009-088727Monitor
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fil
MediumCVSS 6.6No exploitEPSS 2%linux-pam · linux-pamMar 12, 2009
- CVE-2010-385327Monitor
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service
MediumCVSS 6.9No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2014-258324Monitor
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users
MediumCVSS 5.8No exploitEPSS 4%linux-pam · linux-pamApr 10, 2014
- CVE-2024-2236522Monitor
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat c
MediumCVSS 5.5No exploitEPSS 0%linux-pam · linux-pamFeb 6, 2024
- CVE-2010-470619Monitor
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a
MediumCVSS 4.9No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2010-470719Monitor
The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL fi
MediumCVSS 4.9No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2011-314818Monitor
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local use
MediumCVSS 4.6No exploitEPSS 1%linux-pam · linux-pamJul 22, 2012
- CVE-2010-343518Monitor
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories
MediumCVSS 4.7No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2009-057918Monitor
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass i
MediumCVSS 4.6No exploitEPSS 0%linux-pam · linux-pamApr 16, 2009
- CVE-2010-343018Monitor
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required
MediumCVSS 4.7No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2024-1004118Monitor
Pam: libpam: libpam vulnerable to read hashed password
MediumCVSS 4.7No exploitEPSS 0%linux-pam · linux-pamOct 23, 2024
- CVE-2010-331613Monitor
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of th
LowCVSS 3.3No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011
- CVE-2011-31498Monitor
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when
LowCVSS 2.1No exploitEPSS 1%linux-pam · linux-pamJul 22, 2012
- CVE-2010-34317Monitor
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return val
LowCVSS 1.9No exploitEPSS 0%linux-pam · linux-pamJan 24, 2011