Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Pam MEDIUM 5.5
CVE-2024-22365

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for …

Fix: 1.6.0+
Fix from $1,600 2024-02-06
Linux Pam CRITICAL 9.8
CVE-2022-28321

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctl…

Fix: 1.5.2-6.1+
Fix from $2,300 2022-09-19
Linux Pam CRITICAL 9.8
CVE-2020-27780

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM…

Fix: 1.5.1+
Fix from $2,300 2020-12-18
Linux Pam MEDIUM 6.5
CVE-2015-3238

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows loc…

Fix: after 1121
Fix from $1,600 2015-08-24
Linux Pam MEDIUM 5.8
CVE-2014-2583

Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create…

Patch available
Fix from $1,600 2014-04-10
Linux Pam HIGH 7.2
CVE-2010-4708

The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users…

Fix: after 1.1.2
Fix from $1,950 2011-01-24
Linux Pam MEDIUM 6.9
CVE-2010-3853

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during ex…

Fix: after 1.1.2
Fix from $1,600 2011-01-24
Linux Pam MEDIUM 6.6
CVE-2009-0887

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contain…

Fix: after 1.0.3
Fix from $1,600 2009-03-12