CVE detail
CVE-2025-24531
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- http://www.openwall.com/lists/oss-security/2025/02/06/7www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 16, 2026, 6:16 PM - http://www.openwall.com/lists/oss-security/2025/02/06/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 16, 2026, 6:16 PM - https://www.openwall.com/lists/oss-security/2025/02/06/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 16, 2026, 6:16 PM No excerpt available.
Exploitgithub.comJan 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comJan 16, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-55958CVSS 8.3 · High
Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fa…
- CVE-2026-53092CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix linked reg delta tracking when src_reg == dst_reg Consider the case of rX += rX where src_reg and ds…
- CVE-2026-9058CVSS 9.3 · Critical
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the spe…
- CVE-2026-42246CVSS 7.6 · High
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can ca…
- CVE-2025-5987CVSS 8.1 · High
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to li…
- CVE-2025-32414CVSS 5.6 · Medium
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in x…