Shadow

Vendor:

First CVE: Mar 1, 2005 · Active for 21 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Shadow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2005
21 years ago
Most Recent CVE
Mar 17, 2021
1,958 days ago

CVE Severity & Scoring

Shadow8 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local3 (37.5%)
Network0 (0.0%)
Unknown5 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (25.0%)
High1 (12.5%)
Unknown5 (62.5%)
User Interaction
None3 (37.5%)
Unknown5 (62.5%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (62.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on
Dec 9, 20087.227NOYES
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using th
Nov 4, 20197.825NONO
The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less use
Mar 17, 20217.824NONO
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
Feb 19, 20116.422NONO
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error
Mar 1, 20054.618NONO
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Dec 3, 20194.714NONO
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which ca
May 28, 20063.714NONO
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pp
Apr 19, 20062.112NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Shadow

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.417.80.4%00
4.0.613.70.4%00
4.0.513.70.4%00
4.0.4.124.20.4%00
4.0.413.70.4%00
4.0.213.70.4%00
4.0.18.117.20.9%01
4.0.1412.10.3%00
4.0.113.70.4%00
4.0.013.70.4%00
1\16.42.3%00