Search CVE reports


Toggle filters

41 – 50 of 87 results


CVE-2015-3238

Low priority

Some fixes available 6 of 8

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages

CVE-2014-2583

Low priority

Some fixes available 2 of 6

Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1)...

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages

CVE-2013-7041

Low priority

Some fixes available 2 of 7

The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages

CVE-2013-1052

High priority
Fixed

pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.

1 affected package

pam-xdg-support

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-xdg-support
Show less packages

CVE-2013-0288

Medium priority

Some fixes available 1 of 6

nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large...

1 affected package

nss-pam-ldapd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nss-pam-ldapd
Show less packages

CVE-2013-0191

Medium priority
Ignored

libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.

1 affected package

pam-pgsql

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-pgsql
Show less packages

CVE-2012-2350

Medium priority
Ignored

pam_shield before 0.9.4: Default configuration does not perform protective action

1 affected package

pam-shield

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-shield
Show less packages

CVE-2012-1502

Medium priority

Some fixes available 4 of 5

Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.

1 affected package

python-pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pam
Show less packages

CVE-2011-3628

Medium priority
Fixed

Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before...

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages

CVE-2011-3149

Medium priority
Fixed

The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial...

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages