Vulnerabilities > Chetcpasswd

DATE CVE VULNERABILITY TITLE RISK
2006-12-21 CVE-2006-6681 Resource Management Errors vulnerability in Chetcpasswd 2.3.3
Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.
network
low complexity
chetcpasswd CWE-399
7.5
2006-12-21 CVE-2006-6680 Information Disclosure vulnerability in Chetcpasswd 2.2.1
Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file.
local
low complexity
chetcpasswd
4.6
2006-12-19 CVE-2006-6639 Local Privilege Escalation vulnerability in Chetcpasswd 2.4.1
Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.
local
low complexity
chetcpasswd
4.6
2002-12-31 CVE-2002-2221 Local Privilege Escalation vulnerability in Chetcpasswd 2.3.1/2.3.3/2.4.1
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary.
local
high complexity
chetcpasswd
6.2
2002-12-31 CVE-2002-2220 Local Security vulnerability in Chetcpasswd 1.12
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
local
high complexity
chetcpasswd
6.2
2002-12-31 CVE-2002-2219 Unspecified vulnerability in Chetcpasswd 2.1
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.
network
low complexity
chetcpasswd
7.5