Search CVE reports


Toggle filters

11 – 20 of 28 results


CVE-2017-20002

Medium priority
Not affected

The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by...

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow Not affected Not affected
Show less packages

CVE-2017-15924

Medium priority
Ignored

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config,...

1 affected package

shadowsocks-libev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadowsocks-libev Not affected
Show less packages

CVE-2017-12424

Low priority

Some fixes available 2 of 4

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other...

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow Not affected Not affected Not affected
Show less packages

CVE-2016-6252

Medium priority

Some fixes available 4 of 6

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow
Show less packages

CVE-2016-6251

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow
Show less packages

CVE-2013-4235

Low priority

Some fixes available 2 of 20

shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow Not affected Fixed Vulnerable Vulnerable
Show less packages

CVE-2011-0721

Medium priority
Fixed

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow
Show less packages

CVE-2010-1151

Medium priority
Ignored

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper...

1 affected package

libapache2-mod-auth-shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-shadow
Show less packages

CVE-2008-5394

Medium priority
Fixed

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line...

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow
Show less packages

CVE-2008-5104

High priority
Fixed

Ubuntu 6.06 LTS, 7.10, 8.04 LTS, and 8.10, when installed as a virtual machine by (1) python-vm-builder or (2) ubuntu-vm-builder in VMBuilder 0.9 in Ubuntu 8.10, have ! (exclamation point) as the default root password, which...

1 affected package

shadow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shadow
Show less packages