Chetcpasswd is a narrowly scoped password-management utility with a focused vulnerability footprint concentrated in its single product. While characterized by unclassified weakness categories in available disclosures, the vendor's vulnerabilities tend to acquire public exploit code, making timely patching important for deployments relying on this tool. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chetcpasswd over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2219HIGH chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field. | Dec 31, 2002 | 7.5 | 30 | NO | YES |
CVE-2006-6679HIGH Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unaut | Dec 21, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-6681HIGH Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack. | Dec 21, 2006 | 7.5 | 19 | NO | NO |
CVE-2002-2220MEDIUM Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors. | Dec 31, 2002 | 6.2 | 17 | NO | NO |
CVE-2002-2221MEDIUM Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binar | Dec 31, 2002 | 6.2 | 17 | NO | NO |
CVE-2006-6682MEDIUM Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remot | Dec 21, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-6680MEDIUM Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by | Dec 21, 2006 | 4.6 | 14 | NO | NO |
CVE-2006-6639MEDIUM Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program | Dec 19, 2006 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chetcpasswd.
Media articles that mention a CVE ID that affects a product developed by Chetcpasswd — matched by CVE ID, not by vendor name.