← Back

Chetcpasswd

chetcpasswd

Vendor: Chetcpasswd • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chetcpasswd
1Chetcpasswd
Apr 23, 2026
Dec 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.
1Chetcpasswd
1Chetcpasswd
Apr 23, 2026
Dec 21, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file.
1Chetcpasswd
1Chetcpasswd
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the po...Show more
Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.Show less
1Chetcpasswd
1Chetcpasswd
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2...Show more
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639.Show less
1Chetcpasswd
1Chetcpasswd
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
1Chetcpasswd
1Chetcpasswd
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.