Pam MySQL is a PAM (pluggable authentication module) for Linux systems that integrates MySQL credential validation into system authentication, serving a narrow but established deployment niche. The observed vulnerability signal centers on the authentication module itself, with the primary weakness class reflecting general or uncategorized issues in the disclosure record. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pam Mysql over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0056HIGH Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a | Feb 13, 2006 | 7.5 | 21 | NO | NO |
CVE-2000-0957HIGH The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plain | Dec 19, 2000 | 7.5 | 19 | NO | NO |
CVE-2005-4713MEDIUM Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fa | Dec 31, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pam Mysql.
Media articles that mention a CVE ID that affects a product developed by Pam Mysql — matched by CVE ID, not by vendor name.