Debian / Shadow
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-20002 | The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login… | HIGH | 7.8 | Mar 17, 2021 |
| CVE-2013-4235 | shadow-utils: TOCTOU race conditions by copying and removing directory trees | MEDIUM | 4.7 | Dec 3, 2019 |
| CVE-2005-4890 | coreutils: tty hijacking possible in "su" via TIOCSTI ioctl | HIGH | 7.8 | Nov 4, 2019 |
| CVE-2011-0721 | shadow: Multiple CRLF injections in chfn and chsh | MEDIUM | 6.4 | Feb 18, 2011 |
| CVE-2008-5394 | /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files vi… | HIGH | 7.2 | Dec 9, 2008 |
| CVE-2006-1174 | security flaw | LOW | 3.7 | May 28, 2006 |
| CVE-2006-1844 | The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including prese… | LOW | 2.1 | Apr 19, 2006 |
| CVE-2004-1001 | Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized acti… | MEDIUM | 4.6 | Nov 4, 2004 |
Showing 1 to 8 of 8 CVEs