Skip to content
Noroxi

Linux-PAM records

18 published records for vendor linux-pam.

All records

18 records
  • A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.

    CriticalCVSS 9.8No exploitEPSS 2%

    linux-pam · linux-pamDec 17, 2020

  • The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.

    CriticalCVSS 9.8No exploitEPSS 1%

    linux-pam · linux-pamSep 19, 2022

  • CVE-2010-4708
    28Monitor

    The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lo

    HighCVSS 7.2No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • CVE-2015-3238
    27Monitor

    The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, a

    MediumCVSS 6.5No exploitEPSS 3%

    linux-pam · linux-pamAug 24, 2015

  • CVE-2009-0887
    27Monitor

    Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fil

    MediumCVSS 6.6No exploitEPSS 2%

    linux-pam · linux-pamMar 12, 2009

  • CVE-2010-3853
    27Monitor

    pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service

    MediumCVSS 6.9No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • CVE-2014-2583
    24Monitor

    Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users

    MediumCVSS 5.8No exploitEPSS 4%

    linux-pam · linux-pamApr 10, 2014

  • linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat c

    MediumCVSS 5.5No exploitEPSS 0%

    linux-pam · linux-pamFeb 6, 2024

  • CVE-2010-4706
    19Monitor

    The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a

    MediumCVSS 4.9No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • CVE-2010-4707
    19Monitor

    The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL fi

    MediumCVSS 4.9No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • CVE-2011-3148
    18Monitor

    Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local use

    MediumCVSS 4.6No exploitEPSS 1%

    linux-pam · linux-pamJul 22, 2012

  • CVE-2010-3435
    18Monitor

    The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories

    MediumCVSS 4.7No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • CVE-2009-0579
    18Monitor

    Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass i

    MediumCVSS 4.6No exploitEPSS 0%

    linux-pam · linux-pamApr 16, 2009

  • CVE-2010-3430
    18Monitor

    The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required

    MediumCVSS 4.7No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • Pam: libpam: libpam vulnerable to read hashed password

    MediumCVSS 4.7No exploitEPSS 0%

    linux-pam · linux-pamOct 23, 2024

  • CVE-2010-3316
    13Monitor

    The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of th

    LowCVSS 3.3No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011

  • The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when

    LowCVSS 2.1No exploitEPSS 1%

    linux-pam · linux-pamJul 22, 2012

  • The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return val

    LowCVSS 1.9No exploitEPSS 0%

    linux-pam · linux-pamJan 24, 2011