CVE Tools

Linux-pam

13 CVEs tracked since 2009. Since Apr 2009, none of them reached CISA KEV.

Linux-pam CVEs per month

Apr 2009 to Aug 2015. Point at a month, or focus the strip and use the arrow keys.
Linux-pam CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2009-0410
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-0180
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-0720
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-0410
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-0810

Products

The products that kept showing up in Linux-pam's monthly top three, with their CVEs summed over those months.

  1. Linux-pam135 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Linux-pam.

  1. CVE-2026-54411Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison5.9
  2. CVE-2024-10041Pam: libpam: libpam vulnerable to read hashed password4.7
  3. CVE-2024-22365linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.5.5
  4. CVE-2022-28321The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from...9.8
  5. CVE-2020-27780A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case o...9.8
  6. CVE-2015-3238The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denia...6.5
  7. CVE-2014-2583Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authenticati...5.8
  8. CVE-2011-3149The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allow...2.1
  9. CVE-2011-3148Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly exec...4.6
  10. CVE-2010-4706The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might a...4.9
  11. CVE-2010-4708The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment ...7.2
  12. CVE-2010-4707The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to ca...4.9
  13. CVE-2010-3853pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which migh...6.9
  14. CVE-2010-3431The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local u...1.9
  15. CVE-2010-3430The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow l...4.7

The record

Peak rank
#19 in Jan 2011
Busiest month shown
Jan 2011, 8 CVEs
Months with a KEV entry
0 since Apr 2009
Monthly snapshots
5 since 2009
Linux-pam's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store