Search CVE reports


Toggle filters

71 – 80 of 87 results


CVE-2008-3970

Low priority
Ignored

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.

1 affected package

libpam-mount

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-mount
Show less packages

CVE-2008-3825

Medium priority
Not affected

pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges...

1 affected package

libpam-krb5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-krb5
Show less packages

CVE-2008-2516

Medium priority

Some fixes available 5 of 7

pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal...

1 affected package

pam-pgsql

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-pgsql
Show less packages

CVE-2007-6418

Medium priority
Fixed

The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.

1 affected package

dspam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dspam
Show less packages

CVE-2007-2873

Medium priority

Some fixes available 5 of 8

SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack...

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin
Show less packages

CVE-2007-0844

Medium priority
Not affected

The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank...

1 affected package

libpam-ssh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-ssh
Show less packages

CVE-2007-0451

Medium priority

Some fixes available 6 of 8

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin
Show less packages

CVE-2007-0003

Medium priority
Not affected

pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam
Show less packages

CVE-2006-5170

Medium priority
Fixed

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control...

1 affected package

libpam-ldap

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-ldap
Show less packages

CVE-2006-2447

Medium priority
Fixed

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin
Show less packages