Shadow
Vendor:
First CVE: Mar 1, 2005 · Active for 21 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Shadow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2005
21 years ago
Most Recent CVE
Mar 17, 2021
1,958 days ago
CVE Severity & Scoring
Shadow8 CVEs
25%
38%
38%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (37.5%)
Network0 (0.0%)
Unknown5 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (25.0%)
High1 (12.5%)
Unknown5 (62.5%)
User Interaction
None3 (37.5%)
Unknown5 (62.5%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (62.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5394HIGH /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on | Dec 9, 2008 | 7.2 | 27 | NO | YES |
CVE-2005-4890HIGH There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using th | Nov 4, 2019 | 7.8 | 25 | NO | NO |
CVE-2017-20002HIGH The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less use | Mar 17, 2021 | 7.8 | 24 | NO | NO |
CVE-2011-0721MEDIUM Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field. | Feb 19, 2011 | 6.4 | 22 | NO | NO |
CVE-2004-1001MEDIUM Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error | Mar 1, 2005 | 4.6 | 18 | NO | NO |
CVE-2013-4235MEDIUM shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees | Dec 3, 2019 | 4.7 | 14 | NO | NO |
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which ca | May 28, 2006 | 3.7 | 14 | NO | NO |
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pp | Apr 19, 2006 | 2.1 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Shadow
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.4 | 1 | 7.8 | 0.4% | 0 | 0 |
| 4.0.6 | 1 | 3.7 | 0.4% | 0 | 0 |
| 4.0.5 | 1 | 3.7 | 0.4% | 0 | 0 |
| 4.0.4.1 | 2 | 4.2 | 0.4% | 0 | 0 |
| 4.0.4 | 1 | 3.7 | 0.4% | 0 | 0 |
| 4.0.2 | 1 | 3.7 | 0.4% | 0 | 0 |
| 4.0.18.1 | 1 | 7.2 | 0.9% | 0 | 1 |
| 4.0.14 | 1 | 2.1 | 0.3% | 0 | 0 |
| 4.0.1 | 1 | 3.7 | 0.4% | 0 | 0 |
| 4.0.0 | 1 | 3.7 | 0.4% | 0 | 0 |
| 1\ | 1 | 6.4 | 2.3% | 0 | 0 |