LiveActive security incident?Get immediate response
CVE archive

2015 CVE Archive

Browse CVE records published in 2015 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 8111 matching CVEs · Page 16 of 163.

Unknown · CVSS Not scored

CVE-2015-9542: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input pass...

add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.

Published Feb 24, 2020 · Updated Aug 6, 2024