VYPR
Vendor

Chetcpasswd

Products
2
CVEs
13
Across products
13
Status
Private

Products

2

Recent CVEs

13
  • CVE-2006-6679HigDec 21, 2006
    risk 0.49cvss 7.5epss 0.02

    Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.

  • CVE-2002-2219Dec 31, 2002
    risk 0.03cvss epss 0.06

    chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.

  • CVE-2008-7250Dec 30, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log.…

  • CVE-2008-7249Dec 30, 2009
    risk 0.00cvss epss 0.04

    Buffer overflow in Squid Analysis Report Generator (Sarg) 2.2.3.1, and probably later, allows user-assisted remote attackers to execute arbitrary code via a long HTTP request method in a crafted access.log file, a different vulnerability than CVE-2008-1167.

  • CVE-2006-6682Dec 21, 2006
    risk 0.00cvss epss 0.02

    Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system.

  • CVE-2006-6685Dec 21, 2006
    risk 0.00cvss epss 0.00

    Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details…

  • CVE-2006-6683Dec 21, 2006
    risk 0.00cvss epss 0.01

    Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might allow remote attackers to bypass intended restrictions implemented through PAM.

  • CVE-2006-6684Dec 21, 2006
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd before 2.4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long X-Forwarded-For HTTP header. NOTE: The provenance of this information is unknown; the…

  • CVE-2006-6681Dec 21, 2006
    risk 0.00cvss epss 0.01

    Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.

  • CVE-2006-6680Dec 21, 2006
    risk 0.00cvss epss 0.00

    Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file.

  • CVE-2006-6639Dec 19, 2006
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.

  • CVE-2002-2221Dec 31, 2002
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639.

  • CVE-2002-2220Dec 31, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.