İçeriğe atla
Noroxi

Linux-PAM kayıtları

linux-pam üreticisine ait 18 yayımlanmış kayıt.

Tüm kayıtlar

18 kayıt
  • CVE-2020-27780
    40Planlayın

    A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users.

    KritikCVSS 9,8İstismar yokEPSS %2

    linux-pam · linux-pam17 Ara 2020

  • CVE-2022-28321
    39İzleyin

    The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins.

    KritikCVSS 9,8İstismar yokEPSS %1

    linux-pam · linux-pam19 Eyl 2022

  • CVE-2010-4708
    28İzleyin

    The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow lo

    YüksekCVSS 7,2İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2015-3238
    27İzleyin

    The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, a

    OrtaCVSS 6,5İstismar yokEPSS %3

    linux-pam · linux-pam24 Ağu 2015

  • CVE-2009-0887
    27İzleyin

    Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration fil

    OrtaCVSS 6,6İstismar yokEPSS %2

    linux-pam · linux-pam12 Mar 2009

  • CVE-2010-3853
    27İzleyin

    pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service

    OrtaCVSS 6,9İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2014-2583
    24İzleyin

    Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users

    OrtaCVSS 5,8İstismar yokEPSS %4

    linux-pam · linux-pam10 Nis 2014

  • CVE-2024-22365
    22İzleyin

    linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat c

    OrtaCVSS 5,5İstismar yokEPSS %0

    linux-pam · linux-pam6 Şub 2024

  • CVE-2010-4706
    19İzleyin

    The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a

    OrtaCVSS 4,9İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2010-4707
    19İzleyin

    The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL fi

    OrtaCVSS 4,9İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2011-3148
    18İzleyin

    Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local use

    OrtaCVSS 4,6İstismar yokEPSS %1

    linux-pam · linux-pam22 Tem 2012

  • CVE-2010-3435
    18İzleyin

    The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories

    OrtaCVSS 4,7İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2009-0579
    18İzleyin

    Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass i

    OrtaCVSS 4,6İstismar yokEPSS %0

    linux-pam · linux-pam16 Nis 2009

  • CVE-2010-3430
    18İzleyin

    The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required

    OrtaCVSS 4,7İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2024-10041
    18İzleyin

    Pam: libpam: libpam vulnerable to read hashed password

    OrtaCVSS 4,7İstismar yokEPSS %0

    linux-pam · linux-pam23 Eki 2024

  • CVE-2010-3316
    13İzleyin

    The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of th

    DüşükCVSS 3,3İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011

  • CVE-2011-3149
    8İzleyin

    The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when

    DüşükCVSS 2,1İstismar yokEPSS %1

    linux-pam · linux-pam22 Tem 2012

  • CVE-2010-3431
    7İzleyin

    The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return val

    DüşükCVSS 1,9İstismar yokEPSS %0

    linux-pam · linux-pam24 Oca 2011