chetcpasswd CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

chetcpasswd vulnerability overview

Aggregates CVE and security vulnerability intelligence across all chetcpasswd-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk buffer overflow and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2006-6681 Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack. [email protected] 7.5 1.40% 2006-12-21 2026-06-16
CVE-2006-6680 Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file. [email protected] 4.6 0.29% 2006-12-21 2026-06-16
CVE-2006-6639 Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line. [email protected] 4.6 0.28% 2006-12-19 2026-06-16
CVE-2002-2221 Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639. [email protected] 6.2 0.27% 2002-12-31 2026-06-16
CVE-2002-2220 Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors. [email protected] 6.2 0.25% 2002-12-31 2026-06-16
CVE-2002-2219 chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field. [email protected] 7.5 6.04% 2002-12-31 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence