Shadow Project / Shadow
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-29383 | shadow: Improper input validation in shadow-utils package utility chfn | MEDIUM | 5.5 | Apr 14, 2023 |
| CVE-2019-19882 | shadow-utils: local users can obtain root access because setuid programs are misconfigured | HIGH | 7.8 | Dec 18, 2019 |
| CVE-2013-4235 | shadow-utils: TOCTOU race conditions by copying and removing directory trees | MEDIUM | 4.7 | Dec 3, 2019 |
| CVE-2018-7169 | shadow-utils: newgidmap allows unprivileged user to drop supplementary groups potentially allowing privilege escalation | MEDIUM | 5.3 | Feb 15, 2018 |
| CVE-2017-12424 | shadow-utils: Buffer overflow via newusers tool | CRITICAL | 9.8 | Aug 4, 2017 |
| CVE-2016-6252 | shadow-utils: Incorrect integer handling results in LPE | HIGH | 7.8 | Feb 17, 2017 |
Showing 1 to 6 of 6 CVEs