Known vulnerabilities in shadow

Software: shadow
Software CPE: cpe:2.3:a:mark_florian:shadow:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting shadow shadow is affected by 9 known vulnerabilities: 1 high, 1 medium, 7 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113028 - Permissions, Privileges, and Access Controls
CVE-2024-56433
CWE-264 Medium
No
No
4.17.1 17.07.2025 SB2025071777
SB2025071778
SB2025071779
and 5 more
#VU80801 - Exposure of sensitive information to an unauthorized actor
CVE-2023-4641
CWE-200 Low
No
No
4.14.0 14.09.2023 SB2023091453
SB2023091455
SB2023101019
and 66 more
#VU75589 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2023-29383
CWE-74 Low
No
No
- 28.04.2023 SB2023042839
SB2023042840
SB2023042841
and 12 more
#VU59131 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2013-4235
CWE-367 Low
No
No
4.11 03.01.2022 SB2022010306
SB2022103110
SB2022112819
and 23 more
#VU23780 - Permissions, Privileges, and Access Controls
CVE-2019-19882
CWE-264 Low
No
No
4.8.1 20.12.2019 SB2019122023
SB2019122024
SB2020082519
#VU11179 - Permissions, Privileges, and Access Controls
CVE-2018-7169
CWE-264 Low
No
No
- 20.03.2018 SB2018021518
SB2018052306
SB2022012713
and 2 more
#VU32061 - Memory corruption
CVE-2017-12424
CWE-119 High
No
No
4.5 04.08.2017 SB2017080405
SB2017112941
SB2017101502
and 2 more
#VU6432 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2017-2616
CWE-362 Low
No
No
- 05.05.2017 SB2017022501
SB2017050512
SB2017051604
and 12 more
#VU6431 - Integer overflow
CVE-2016-6252
CWE-190 Low
No
No
- 05.05.2017 SB2016072203
SB2017050512
SB2017051604
and 3 more