Linux-PAM kayıtları
linux-pam üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %94,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-27780İstismar yok | A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.linux-pam · linux-pam · CWE-287 | Kritik9,8 | — | %2,0 | 17 Ara 2020 |
39İzleyin | CVE-2022-28321İstismar yok | The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.linux-pam · linux-pam · CWE-287 | Kritik9,8 | — | %1,5 | 19 Eyl 2022 |
28İzleyin | CVE-2010-4708İstismar yok | The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lolinux-pam · linux-pam | Yüksek7,2 | — | %0,4 | 24 Oca 2011 |
27İzleyin | CVE-2015-3238İstismar yok | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, alinux-pam · linux-pam · CWE-200 | Orta6,5 | — | %2,7 | 24 Ağu 2015 |
27İzleyin | CVE-2009-0887İstismar yok | Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fillinux-pam · linux-pam · CWE-189 | Orta6,6 | — | %1,9 | 12 Mar 2009 |
27İzleyin | CVE-2010-3853İstismar yok | pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service linux-pam · linux-pam | Orta6,9 | — | %0,4 | 24 Oca 2011 |
24İzleyin | CVE-2014-2583İstismar yok | Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users linux-pam · linux-pam · CWE-22 | Orta5,8 | — | %4,1 | 10 Nis 2014 |
22İzleyin | CVE-2024-22365İstismar yok | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat clinux-pam · linux-pam · CWE-664 | Orta5,5 | — | %0,5 | 6 Şub 2024 |
19İzleyin | CVE-2010-4706İstismar yok | The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle alinux-pam · linux-pam | Orta4,9 | — | %0,4 | 24 Oca 2011 |
19İzleyin | CVE-2010-4707İstismar yok | The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL filinux-pam · linux-pam · CWE-399 | Orta4,9 | — | %0,4 | 24 Oca 2011 |
18İzleyin | CVE-2011-3148İstismar yok | Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local uselinux-pam · linux-pam · CWE-119 | Orta4,6 | — | %0,7 | 22 Tem 2012 |
18İzleyin | CVE-2010-3435İstismar yok | The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directorieslinux-pam · linux-pam | Orta4,7 | — | %0,4 | 24 Oca 2011 |
18İzleyin | CVE-2009-0579İstismar yok | Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass ilinux-pam · linux-pam · CWE-264 | Orta4,6 | — | %0,3 | 16 Nis 2009 |
18İzleyin | CVE-2010-3430İstismar yok | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the requiredlinux-pam · linux-pam | Orta4,7 | — | %0,3 | 24 Oca 2011 |
18İzleyin | CVE-2024-10041İstismar yok | Pam: libpam: libpam vulnerable to read hashed passwordlinux-pam · linux-pam · CWE-922 | Orta4,7 | — | %0,3 | 23 Eki 2024 |
13İzleyin | CVE-2010-3316İstismar yok | The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of thlinux-pam · linux-pam | Düşük3,3 | — | %0,4 | 24 Oca 2011 |
8İzleyin | CVE-2011-3149İstismar yok | The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle whenlinux-pam · linux-pam · CWE-119 | Düşük2,1 | — | %0,5 | 22 Tem 2012 |
7İzleyin | CVE-2010-3431İstismar yok | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return vallinux-pam · linux-pam | Düşük1,9 | — | %0,3 | 24 Oca 2011 |
- CVE-2020-2778040Planlayın
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.
KritikCVSS 9,8İstismar yokEPSS %2linux-pam · linux-pam17 Ara 2020
- CVE-2022-2832139İzleyin
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.
KritikCVSS 9,8İstismar yokEPSS %1linux-pam · linux-pam19 Eyl 2022
- CVE-2010-470828İzleyin
The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lo
YüksekCVSS 7,2İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2015-323827İzleyin
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, a
OrtaCVSS 6,5İstismar yokEPSS %3linux-pam · linux-pam24 Ağu 2015
- CVE-2009-088727İzleyin
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fil
OrtaCVSS 6,6İstismar yokEPSS %2linux-pam · linux-pam12 Mar 2009
- CVE-2010-385327İzleyin
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service
OrtaCVSS 6,9İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2014-258324İzleyin
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users
OrtaCVSS 5,8İstismar yokEPSS %4linux-pam · linux-pam10 Nis 2014
- CVE-2024-2236522İzleyin
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat c
OrtaCVSS 5,5İstismar yokEPSS %0linux-pam · linux-pam6 Şub 2024
- CVE-2010-470619İzleyin
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a
OrtaCVSS 4,9İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2010-470719İzleyin
The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL fi
OrtaCVSS 4,9İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2011-314818İzleyin
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local use
OrtaCVSS 4,6İstismar yokEPSS %1linux-pam · linux-pam22 Tem 2012
- CVE-2010-343518İzleyin
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories
OrtaCVSS 4,7İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2009-057918İzleyin
Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass i
OrtaCVSS 4,6İstismar yokEPSS %0linux-pam · linux-pam16 Nis 2009
- CVE-2010-343018İzleyin
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required
OrtaCVSS 4,7İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2024-1004118İzleyin
Pam: libpam: libpam vulnerable to read hashed password
OrtaCVSS 4,7İstismar yokEPSS %0linux-pam · linux-pam23 Eki 2024
- CVE-2010-331613İzleyin
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of th
DüşükCVSS 3,3İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011
- CVE-2011-31498İzleyin
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when
DüşükCVSS 2,1İstismar yokEPSS %1linux-pam · linux-pam22 Tem 2012
- CVE-2010-34317İzleyin
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return val
DüşükCVSS 1,9İstismar yokEPSS %0linux-pam · linux-pam24 Oca 2011