Search CVE reports


Toggle filters

31 – 40 of 87 results


CVE-2019-12209

Medium priority
Vulnerable

Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on...

1 affected package

pam-u2f

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam-u2f Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-17953

Low priority
Not affected

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).

1 affected package

pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pam Not affected
Show less packages

CVE-2018-11781

Low priority
Fixed

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2018-11780

Medium priority
Fixed

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2017-15705

Medium priority
Fixed

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts....

1 affected package

spamassassin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spamassassin Fixed
Show less packages

CVE-2018-10380

Medium priority
Vulnerable

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

2 affected packages

kwallet-pam, pam-kwallet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kwallet-pam Not affected Not affected Not affected Vulnerable
pam-kwallet Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-9275

Medium priority
Needs evaluation

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device)...

1 affected package

yubico-pam

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
yubico-pam Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2017-12197

Medium priority
Fixed

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access...

1 affected package

libpam4j

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam4j
Show less packages

CVE-2017-11737

Medium priority
Not affected

interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

1 affected package

rspamd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rspamd Not affected Not in release
Show less packages

CVE-2016-4422

High priority

Some fixes available 3 of 4

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.

1 affected package

libpam-sshauth

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpam-sshauth
Show less packages