McDope
5 exploits
Active since May 2026
pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulation
CVSS 6.3
pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result
CVSS 6.3
pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local
CVSS 7.4
pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result
CVSS 6.3
pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash
CVSS 5.1