Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Util Linux MEDIUM 6.7
CVE-2020-21583

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when s…

Fix: 2.27+
Fix from $1,600 2023-08-22
Util Linux MEDIUM 5.5
CVE-2022-0563

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment va…

Fix: 2.37.4+
Fix from $1,600 2022-02-21
Util Linux MEDIUM 5.5
CVE-2021-37600

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way th…

Fix: after 2.37.1
Fix from $1,600 2021-07-30
Linux Pam HIGH 8.1
CVE-2018-17953

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead…

Mitigation only
Fix from $1,950 2018-11-27
Util Linux HIGH 7.8
CVE-2018-7738

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which i…

Fix: after 2.31
Fix from $1,950 2018-03-07
Util Linux CRITICAL 9.8
CVE-2015-5224

The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other atta…

Fix: after 2.26.2
Fix from $2,300 2017-08-23
Util Linux HIGH 7.8
CVE-2016-2779

runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's …

Mitigation only
Fix from $1,950 2017-02-07
Util Linux MEDIUM 5.5
CVE-2001-1494

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log f…

Fix: 2.11n+
Fix from $1,600 2001-12-31