Vulnerabilities (CVE)

Filtered by vendor Andrew Morgan Subscribe
Filtered by product Linux Pam
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-0003 1 Andrew Morgan 1 Linux Pam 2024-02-28 7.2 HIGH N/A
pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.
CVE-2003-0388 1 Andrew Morgan 1 Linux Pam 2024-02-28 4.6 MEDIUM N/A
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.