Lucene search

K

Pam Security Vulnerabilities

cve
cve

CVE-2002-1227

PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.

7AI Score

0.008EPSS

2004-09-01 04:00 AM
28
cve
cve

CVE-2005-2977

The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.

6.2AI Score

0.0004EPSS

2005-11-01 12:47 PM
29
cve
cve

CVE-2020-27780

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

9.8CVSS

9.2AI Score

0.002EPSS

2020-12-18 12:15 AM
85
3